Impact Evaluation of CVE‑2026‑31431 ("Copy Fail") of VMware by Broadcom product portfolio
search cancel

Impact Evaluation of CVE‑2026‑31431 ("Copy Fail") of VMware by Broadcom product portfolio

book

Article ID: 439189

calendar_today

Updated On:

Products

VMware vSphere Kubernetes Service VMware vCenter Server VMware vSphere ESXi VMware NSX VMware Avi Load Balancer VMware SDDC Manager / VCF Installer VMware Aria Operations (formerly vRealize Operations) 8.x VCF Operations/Automation (formerly VMware Aria Suite)

Issue/Introduction

A high-severity local privilege escalation (LPE) vulnerability, designated as CVE-2026-31431 (commonly referred to as "Copy Fail", rated with Base Score 7.8 by kernel.org), has been publicly disclosed on April 22, 2026 affecting the Linux kernel. This vulnerability allows an unprivileged local attacker to trigger a deterministic, controlled memory write into the page cache. Successful exploitation on affected Linux kernels results in unauthorized escalation to root privileges and can facilitate cross-container impacts or container escape scenarios in shared environments.

Environment

VMware Photon OS
VMware vSphere Kubernetes Service
VMware vCenter Server
VMware ESXi
VMware SDDC Manager
VMware Aria Suite
VMware NSX
VMware vCloud
Telco Cloud Automation 

Cause

The vulnerability is caused by a logic flaw within the algif_aead Linux kernel module of the AF_ALG (userspace crypto API) in the Linux kernel's cryptographic subsystem. Due to an improper memory handling optimization introduced in 2017, an attacker can corrupt the in-memory cache of privileged binaries (such as setuid binaries) without altering the physical file on disk and gain root privileges.

For a successful exploitation, an attacker requires network and authenticated access to the relevant system. As per today, this vulnerability can not be exploited remotely or without previously being successfully authenticated to the system in question.

Resolution

ProductExploitable/Fixed inNotes
VMware ESXiNoVMware ESXi is not based on Linux, and hence is not affected.
VMware Photon OSNoPhoton OS does not utilize the algif_aead kernel module, and hence is not affected.
VMware vCenter ServerNoVirtual Appliance is based on Photon OS, and hence is not affected.
VMware vSphere Kubernetes Service - SupervisorNoVirtual Appliance is based on Photon OS, and hence is not affected.
VMware Tanzu Kubernetes Release - Photon OS ImagesNoPhoton OS is not affected.
VMware Tanzu Kubernetes Release - Ubuntu ImagesRefer to KB 439866Virtual Appliance is based on Ubuntu OS (22.04 and 24.04)
VMware SDDC ManagerNoVirtual Appliance is based on Photon OS, and hence is not affected.
VMware NSXNo
  • Appliance Exposure Assessment: NSX Manager and Edge appliances operate as closed system on Ubuntu. Standard users are not granted shell access, and only fully authenticated administrators possess console or SSH access. This closed administrative architecture structurally neutralizes the local privilege escalation threat model for the NSX appliance itself.
  • IDS/IPS Capability: The NSX Distributed IDS/IPS cannot detect or prevent CVE-2026-31431. Because the exploit is executed locally within host memory using standard internal system calls, it generates no inspectable network traffic for network-based IDS/IPS engines to analyze.
VMware Aria OperationsNoVirtual Appliance is based on Photon OS, and hence is not affected.
VMware Aria Operations for LogsNoVirtual Appliance is based on Photon OS, and hence is not affected.
VMware Aria AutomationNoVirtual Appliance is based on Photon OS, and hence is not affected.
VMware Aria Automation OrchestratorNoVirtual Appliance is based on Photon OS, and hence is not affected.
VMware Aria Suite Lifecycle ManagerNoVirtual Appliance is based on Photon OS, and hence is not affected.
VMware vCloud DirectorNoVirtual Appliance is based on Photon OS, and hence is not affected.
VMware vCloud Usage MeterNoVirtual Appliance is based on Photon OS, and hence is not affected.
VMware vSphere ReplicationNoVirtual Appliance is based on Photon OS, and hence is not affected.
VMware Live Site RecoveryNoVirtual Appliance is based on Photon OS, and hence is not affected.
Telco Cloud AutomationNoTCA Manager and TCA Control Plane virtual Appliances are based on Photon OS, and hence are not affected.

Latest update: 2026-05-20 11:00 UTC.

Should you require further information or support, contact Broadcom Support.
To be notified on any changes, subscribe to this knowledge base article.