Customers inquiring about the exposure of VMware Live Recovery (VLR) appliances to CVE-2026-46331, a page cache corruption vulnerability in the Linux kernel's network scheduling subsystem (net/sched).
VMware Live Recovery (VLR) 9.0.x
CVE-2026-46331 affects the Linux Traffic Control (tc) framework, specifically the pedit action.
The 6.1.x kernel utilized in VLR 9.0.3 , 9.0.4, 9.0.5 incorporates the necessary architectural changes and fixes that mitigate the page cache corruption flaw.
VMware Live Recovery version 9.0.3 and higher are not impacted by CVE-2026-46331.
KB 447961: Impact Assessment for CVE-2026-46331 for vCenter 8.x