Junglewise Threat Intelligence

CVE-2024-26974: Linux Kernel Intel QAT use-after-free in AER recovery

CVE-2024-26974 · Severity: high · CVSS 7 · Published 2024-05-01

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's Intel QuickAssist Technology (QAT) driver, which provides hardware acceleration for cryptography and compression. During a hardware error recovery process, a timing issue can cause the system to prematurely delete memory that is still in use. This could lead to system instability, crashes, or potentially allow an attacker with local access to compromise the system.

Technical details

A use-after-free (UAF) vulnerability exists in the Intel QAT driver (intel_qat) within the Linux kernel due to a race condition during PCI Advanced Error Reporting (AER) recovery. When a device restart is scheduled, the adf_dev_aer_schedule_reset function may time out after 10 seconds and free the reset_data structure. However, the adf_device_reset_worker may still attempt to access this structure to signal completion after the timeout, leading to a UAF read. An attacker with local low-privileged access could potentially exploit this race condition to cause a kernel crash or execute arbitrary code, though the high attack complexity (requiring a specific timing window during hardware recovery) mitigates the risk. The fix involves using completion_done() to ensure the reset_data structure is only freed by the appropriate thread based on whether a timeout occurred.

Affected products

  • Linux Linux Kernel 3.17 to 4.19.312, 4.20 to 5.4.274, 5.5 to 5.10.215, 5.11 to 5.15.154, 5.16 to 6.1.84, 6.2 to 6.6.24, 6.7 to 6.7.12, 6.8 to 6.8.3

Timeline

  • 2024-02-09: other: Patch authored
  • 2024-04-03: patched: Fix committed to stable branches
  • 2024-05-01: advisory: NVD publication date

References

Related threats