Executive brief
A vulnerability exists in the Linux kernel's Qualcomm Cloud AI (QAIC) accelerator driver. If a user or device sends a data transfer request with a size of zero, the system may attempt to access uninitialized memory. This can lead to a system crash (General Protection Fault), potentially allowing a local attacker to disrupt operations or gain unauthorized access to system resources.
Technical details
The vulnerability is a NULL pointer dereference or uninitialized memory access (General Protection Fault) within the 'accel/qaic' driver of the Linux kernel. The root cause is in the find_and_map_user_pages() function, which returns 0 without allocating a scatter-gather table (sgt) when a DMA transfer request has a length of zero or when a continuation request is received after all bytes are transferred. Subsequent calls to encode_addr_size_pairs() attempt to access this unallocated sgt. A local attacker with access to the QAIC device can trigger this by providing a zero-sized ALP. The issue has been patched by ensuring the function returns -EINVAL in these scenarios.
Affected products
- Linux Linux Kernel 6.4.12 to 6.5, 6.6.114, 6.12.55, 6.17.5
Timeline
- 2025-11-12: advisory: NVD published the CVE record
- 2025-10-14: patched: Fix committed to Linux stable tree