Impact Assessment of CVE-2026-46331 on VMware Live Recovery (VLR)
search cancel

Impact Assessment of CVE-2026-46331 on VMware Live Recovery (VLR)

book

Article ID: 449510

calendar_today

Updated On:

Products

VMware Live Recovery

Issue/Introduction

Customers inquiring about the exposure of VMware Live Recovery (VLR) appliances to CVE-2026-46331, a page cache corruption vulnerability in the Linux kernel's network scheduling subsystem (net/sched).

Environment

VMware Live Recovery (VLR) 9.0.x

Cause

CVE-2026-46331 affects the Linux Traffic Control (tc) framework, specifically the pedit action. 

Resolution

The 6.1.x kernel utilized in VLR 9.0.3 , 9.0.4, 9.0.5 incorporates the necessary architectural changes and fixes that mitigate the page cache corruption flaw.

VMware Live Recovery version 9.0.3 and higher are not impacted by CVE-2026-46331.

Additional Information

KB 447961: Impact Assessment for CVE-2026-46331 for vCenter 8.x