Junglewise Threat Intelligence

CVE-2023-54325: Linux kernel QAT driver out-of-bounds read in AES-CTR

CVE-2023-54325 · Severity: high · CVSS 7.1 · Published 2025-12-30

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

Intel's QuickAssist Technology (QAT) cryptographic driver in the Linux kernel contains a memory safety flaw that allows an out-of-bounds read when processing AES-CTR encryption keys on newer QAT GEN4 hardware. An attacker with access to use the cryptographic interface can trigger this bug, potentially reading sensitive memory contents or causing a system crash.

Technical details

The vulnerability is a out-of-bounds read in the QAT driver's AES-CTR key initialization routine (qat_alg_skcipher_init_com). The root cause is incorrect order of operations: the driver rounds up the key length to a 16-byte boundary before copying the user-provided key, resulting in a memcpy that reads beyond the allocated key buffer. The fix reorders the operations to copy the key first using the original size, then update the internal key length field. This is a local vulnerability requiring cryptographic interface access, fixed by moving two lines of code in drivers/crypto/qat/qat_common/qat_algs.c.

Affected products

  • Linux Linux kernel 6.2-rc1 and earlier versions containing commit 67916c951689

Timeline

  • 2023-02-01: disclosed: Patch authored by Giovanni Cabiddu
  • 2023-03-10: patched: Merged into Linux stable trees
  • 2025-12-30: other: CVE published

References

Related threats