Executive brief
Intel's QuickAssist Technology (QAT) cryptographic driver in the Linux kernel contains a memory safety flaw that allows an out-of-bounds read when processing AES-CTR encryption keys on newer QAT GEN4 hardware. An attacker with access to use the cryptographic interface can trigger this bug, potentially reading sensitive memory contents or causing a system crash.
Technical details
The vulnerability is a out-of-bounds read in the QAT driver's AES-CTR key initialization routine (qat_alg_skcipher_init_com). The root cause is incorrect order of operations: the driver rounds up the key length to a 16-byte boundary before copying the user-provided key, resulting in a memcpy that reads beyond the allocated key buffer. The fix reorders the operations to copy the key first using the original size, then update the internal key length field. This is a local vulnerability requiring cryptographic interface access, fixed by moving two lines of code in drivers/crypto/qat/qat_common/qat_algs.c.
Affected products
- Linux Linux kernel 6.2-rc1 and earlier versions containing commit 67916c951689
Timeline
- 2023-02-01: disclosed: Patch authored by Giovanni Cabiddu
- 2023-03-10: patched: Merged into Linux stable trees
- 2025-12-30: other: CVE published