Executive brief
A security vulnerability exists in Intel QuickAssist Technology (QAT), a hardware accelerator used to speed up intensive tasks like data compression and cryptography in server environments. A highly privileged attacker with local access to the system could exploit a missing protection mechanism in the hardware interface to further escalate their privileges. This could allow an attacker to bypass security boundaries, potentially compromising the confidentiality and integrity of sensitive data across the entire system.
Technical details
A vulnerability classified as CWE-1299 (Missing Protection Mechanism for Alternate Hardware Interface) exists in Intel QuickAssist Technology (QAT) for Intel Xeon 6 with E-cores (Birch Stream) platforms. The flaw resides within the Ring 0 kernel interface where an alternate hardware path lacks sufficient access control granularity. A local adversary with high privileges (e.g., administrative or system-level access) and specialized internal knowledge can exploit this to achieve further escalation of privilege. This exploit can bypass security boundaries (indicated by the CVSS Scope: Changed), impacting the confidentiality and integrity of the system. Intel has released microcode updates to address this issue, and Red Hat has issued corresponding updates for the microcode_ctl package in RHEL 9 and 10.
Affected products
- Intel Xeon 6 with E-cores (Birch Stream) All versions prior to February 2026 microcode update
- Red Hat Enterprise Linux 9 Affected
- Red Hat Enterprise Linux 10 Affected
Timeline
- 2026-02-10: disclosed: Initial advisory release by Intel and NVD publication
- 2026-02-10: patched: Intel released microcode updates and prescriptive guidance
- 2026-04-07: advisory: Red Hat released security advisory RHSA-2026:6888 for RHEL 10.0 EUS
References
- https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01406.html
- https://access.redhat.com/errata/RHSA-2026:6888
- https://access.redhat.com/security/cve/CVE-2025-35998
- https://bugzilla.redhat.com/show_bug.cgi?id=2438523
- https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-35998.json