CVE-2026-31431 Impact and Mitigation for DLVM
search cancel

CVE-2026-31431 Impact and Mitigation for DLVM

book

Article ID: 440380

calendar_today

Updated On:

Products

VCF Private AI Services

Issue/Introduction

A Linux kernel local privilege escalation (LPE) vulnerability, publicly disclosed on April 29, 2026, affects all DLVM releases. The vulnerability is tracked as CVE-2026-31431 and is commonly referred to as "Copy Fail".

The affected component is the algif_aead kernel module, which provides hardware-accelerated AEAD (Authenticated Encryption with Associated Data) cryptographic functions. An unprivileged local user can exploit this vulnerability to escalate privileges to root.

All DLVM releases based on Ubuntu 22.04 (DLVM 9.0.x) and Ubuntu 24.04 (DLVM 9.1.0) are affected.

Environment

VMware Private AI Service 9.0.x
VMware Private AI Service 9.1.0

Cause

No software packages included in the DLVM image utilize algif_aead, and the kernel module is not loaded by default. However, as DLVM is a platform for user-deployed workloads, any custom application that utilizes the AF_ALG socket interface could trigger the on-demand loading of this module, thereby exposing the system to the vulnerability.

Resolution

Broadcom is aware of CVE-2026-31431. Please refer to the release notes for existing and forthcoming product releases for any updates in relation to this CVE.
Should you require further information please contact Broadcom Support.

Additional Information

Impact Evaluation of CVE‑2026‑31431 ("Copy Fail") of VMware by Broadcom product portfolio