Junglewise Threat Intelligence

CVE-2026-20914: Intel QAT software drivers null pointer dereference

CVE-2026-20914 · Severity: medium · CVSS 5.5 · Published 2026-05-12

Technologies: Intel QuickAssist Technology (QAT) Software Drivers for Windows, Intel Quickassist Technology. Vendors: Intel.

Executive brief

Intel QuickAssist Technology (QAT) software drivers for Windows are used to accelerate cryptographic and data compression workloads. A vulnerability in these drivers could allow a local user to crash the system or specific applications, leading to a denial of service. This could disrupt business operations that rely on high-performance data processing.

Technical details

A NULL pointer dereference (CWE-476) exists in certain Intel QAT software drivers for Windows within Ring 3 (User Applications). The vulnerability is triggered when the driver fails to properly validate a pointer before dereferencing it. An unprivileged but authenticated local attacker can exploit this flaw with low complexity to cause a denial of service (system or application crash). The issue is resolved in Intel QAT software driver version 2.6.0 and later. No user interaction is required for exploitation.

Affected products

  • Intel QuickAssist Technology (QAT) software drivers for Windows before 2.6.0

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats