Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability

Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.

Published 26 Aug 2026Updated 26 Aug 2026129 sources
CVSS 7.8 HIGHPoC CANDIDATE△ CISA KEV

What happened

Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.

Affected versions

Kernel: See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
CVE-Intel · Liverwortenuresis371/copyfail-rsExploit and detect CVE-2026-31431 vulnerabilities using a static binary that monitors system integrity and bypasses PAM authentication.LPERustHIGHAnalyzed★ 0⑂ 0EPSS 99.91%CVE data: CNACode indexedUpdated 26 Aug 2026Tags: af-alg, auditd, copyfail, cve, cve-2026-31431, detection-engineering, ebpf, local-privilege-escalationLiverwortenuresis3712026-05-05CandidateCVE-Intel · theori-io/copy-fail-CVE-2026-31431Copy Fail (CVE-2026-31431): 9-year-old Linux kernel LPE found by Theori's Xint CodeLPEPythonHIGHAnalyzed★ 4050⑂ 910EPSS 99.91%CVE data: CNACode indexedUpdated 26 Aug 2026Tags: ai-security, cve-2026-31431, exploit, linux-kernel, privilege-escalation, privilege-escalation-exploits, security-research, theoritheori-io2026-04-29CandidateCVE-Intel · iss4cf0ng/CVE-2026-31431-Linux-Copy-FailRust implementation Exploit/PoC of CVE-2026-31431-Linux-Copy-Fail, allow executing customized shellcode (such as Meterpreter).LPERustHIGHAnalyzed★ 56⑂ 21EPSS 99.91%CVE data: CNACode indexedUpdated 25 Aug 2026Tags: cve, cve-2026-31431, exploit, explotation, linux, linux-vulnerability, poc, privilege-escalationiss4cf0ng2026-04-30CandidateCVE-Intel · EynaExp/Copy-Fail-CVE-2026-31431-modernizedA modernized version of Copy Fail PEExploitPythonHIGHAnalyzed★ 3⑂ 0EPSS 99.91%CVE data: CNACode indexedUpdated 25 Aug 2026EynaExp2026-05-02CandidateCVE-Intel · Dullpurple-sloop726/CVE-2026-31431-Linux-Copy-FailExploit CVE-2026-31431 on Linux using a Rust implementation to achieve local privilege escalation via an arbitrary page cache write primitive.LPERustHIGHAnalyzed★ 3⑂ 0EPSS 99.91%CVE data: CNACode indexedUpdated 25 Aug 2026Tags: af-alg, container-security, copy-fail, cve-2026-31431, educational, explotation, kernel-exploit, linux-vulnerabilityDullpurple-sloop7262026-05-06CandidateCVE-Intel · painoob/Copy-Fail-Exploit-CVE-2026-31431Most Linux LPEs need a race window or a kernel-specific offset. Copy Fail is a straight-line logic flaw, it needs neither. The same 732-byte Python script (or .c elf) roots every Linux distribution shipped since 2017.ExploitPythonHIGHAnalyzed★ 104⑂ 22EPSS 99.91%CVE data: CNACode indexedUpdated 24 Aug 2026painoob2026-04-29CandidateCVE-Intel · 6abc/Copy-Fail-CVE-2026-31431-dirty-frag-CVE-2026-43284ExploitCHIGHAnalyzed★ 1⑂ 0EPSS 99.91%CVE data: CNACode indexedUpdated 24 Aug 20266abc2026-05-05CandidateCVE-Intel · xeloxa/copyfail-exploitCopy Fail (CVE-2026-31431) LPE exploit. A clean, multi-arch Python reimplementation targeting the Linux kernel AF_ALG page cache vulnerability.LPEPythonHIGHAnalyzed★ 24⑂ 4EPSS 99.91%CVE data: CNACode indexedUpdated 24 Aug 2026Tags: af-alg, copy-fail, cve-2026-31431, exploit, linux-kernel, lpe, privilege-escalation, security-researchxeloxa2026-05-04Candidate