Executive brief
The Linux kernel's QAIC (Qualcomm AI Accelerator Interface) driver contains insufficient bounds checking in its message decoding function, allowing malicious or malformed device control messages to bypass validation checks. An attacker with the ability to send crafted messages to the QAIC device could cause memory corruption, information disclosure, or trigger a denial-of-service condition affecting system stability.
Technical details
The vulnerability exists in the decode_message() function within drivers/accel/qaic/qaic_control.c, which processes control path messages for the QAIC accelerator. The function suffers from multiple bounds-checking gaps: it fails to validate that msg_hdr_len is large enough to contain at least one header, does not ensure sufficient space to read the next header, lacks minimum size checks on the trans_hdr->len field, and is susceptible to integer overflow when adding message length values. These weaknesses allow an attacker to cause out-of-bounds memory access, memory corruption via memcpy operations with incorrect length parameters, and potential information leakage. The fix, applied in commit 51b56382ed2a, adds comprehensive bounds validation including size_add() to prevent integer overflow. Local or adjacent network access to the QAIC device's control interface is required to exploit this vulnerability.
Affected products
- Linux Linux Kernel 6.4.x and later before fix (commit 51b56382ed2a)
Timeline
- 2023-07-11: disclosed: Patch authored by Dan Carpenter
- 2023-07-14: patched: Patch committed upstream (commit 51b56382ed2a2b03347372272362b3baa623ed1e)
- 2023-07-27: patched: Backported to stable trees (commit 57d14cb3bae4619ce2fb5235cb318c3d5d8f53fd)
- 2025-10-01: other: CVE-2023-53493 published in NVD