Junglewise Threat Intelligence

CVE-2026-64304: Linux Kernel Intel QAT buffer overflow in RSA CRT component handling

CVE-2026-64304 · Severity: info · CVSS 0 · Published 2026-07-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Intel QuickAssist Technology (QAT) driver could allow for memory corruption. This component is used to accelerate cryptographic operations like RSA encryption. An exploit could lead to system instability or potentially allow an attacker to compromise the security of the operating system.

Technical details

A buffer overflow exists in the qat_rsa_setkey_crt() function within the Intel QAT driver (qat_asym_algs.c). The driver allocates DMA buffers based on half the modulus size (key_sz / 2) but fails to verify that individual CRT components (p, q, dp, dq, qinv) fit within this size. When a component exceeds this limit, a pointer subtraction underflows during a right-alignment memcpy operation, leading to an out-of-bounds write and memory corruption. The fix introduces a length check to ensure components do not exceed the allocated buffer size, falling back to a non-CRT path if they do.

Affected products

  • Linux Linux Kernel 4.8 to 5.10.261, 5.15.164, 6.1.101, 6.6.42, 6.9.11, 6.10.1

Timeline

  • 2026-07-20: disclosed: Initial patch authored by Giovanni Cabiddu
  • 2026-07-24: patched: Patch committed to stable trees by Greg Kroah-Hartman
  • 2026-07-25: advisory: CVE-2026-64304 published

References

Related threats