Product Affected

See below
High

CVSS: v3.1: 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

Problem

The HPE Juniper Networking PSIRT is aware of the Linux kernel vulnerability related to the algif_aead crypto module, known as "Copy Fail", being tracked as CVE-2026-31431.

Copy Fail is a logic bug in the crypto module's authencesn cryptographic template. It lets an unprivileged local user trigger a deterministic, controlled 4-byte write into the page cache of any readable file on the system.

Below is the current status of Juniper Networking products potentially impacted by the Copy Fail vulnerability:

ProductStatus
Junos OSNot Vulnerable: Engineering has confirmed that Junos OS, based loosely on FreeBSD, is not vulnerable to this issue.
Junos OS Evolved (EVO)EVO includes the vulnerable kernel commits and is exploitable, but only from the shell. The exploit describes a local, low-privileged user triggering a deterministic, controlled 4-byte write into the page cache of any readable file on the system. Exploitation is limited to only users with shell privilege.
Session Smart RouterAll versions of Session Smart Router (SSR) are vulnerable to Copy Fail. However, exploitation requires authenticated console access. Engineering is waiting to receive upstream fixes from Red Hat and Oracle. A workaround that customers can apply to their existing versions is being developed, which will be applied to our regularly scheduled LTS release.
VMHOSTNot Exploitable: WRL ships with a vulnerable version of the algif_aead.ko module but it is not enabled in production. Fixes will be applied once the upstream fixes are ready.
 CTP SeriesNot Vulnerable: The vulnerable module algif_aead is not loaded in CTP OS.
 Mist APNot Vulnerable: Mist APs do not ship with (or enable) the vulnerable kernel module. The risk is further mitigated as access to the Linux shell is tightly controlled. Direct SSH access is not exposed to end users, local SSH is disabled, and remote SSH access is only available via Mist Cloud with 2FA enforcement. Based on the current design, MIST AP customers are protected from this attack vector.
Mist EdgeNot Vulnerable: Confirmed that the algif_aead module is not running on Mist Edge.
 Junos SpaceAll versions of Junos Space are vulnerable to this issue. Awaiting upstream fixes.
ApstraNot Vulnerable: The Apstra VM doesn't load algif_aead into the kernel modules.


Other products not listed above are still under investigation.

 

Unless otherwise noted, this issue affects all software versions of the products listed above.

 

Juniper SIRT is not aware of any malicious exploitation of this vulnerability.

This issue was discovered by a third-party upstream provider.

Solution

Software releases will be updated to resolve this issue and made available on the Customer Support Downloads site.

 

Note: Juniper SIRT's policy is not to evaluate releases that are beyond End of Engineering (EOE) or End of Life (EOL).

Workaround

For most products, successful exploitation requires direct access to the system shell or console. Security best practices for limiting shell access (EVO) or console access (SSR, Mist) to the system will mitigate the risk of malicious exploitation.

Severity Assessment

Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories."

Modification History

2026-05-07: Initial Publication
2026-05-11: Added response for Mist Edge
2026-06-01: Added statement for Apstra

Related Information