Executive brief
A vulnerability was identified in the Linux kernel's QuickAssist Technology (QAT) driver, which is used for hardware acceleration of cryptographic and compression tasks. Under specific conditions where services are being registered or unregistered simultaneously with device initialization or shutdown, the system could experience memory corruption or a crash. This could lead to a denial of service, impacting the availability of systems relying on QAT hardware acceleration.
Technical details
A race condition exists in the Intel QuickAssist Technology (QAT) driver framework within the Linux kernel. The 'service_table' list is protected by 'service_lock' during addition and removal, but several functions (including adf_dev_init, adf_dev_start, and adf_dev_stop) iterate over the list without holding the lock. A concurrent call to adf_service_register() or adf_service_unregister() during these iterations can result in list corruption or a use-after-free (UAF) vulnerability. The fix involves ensuring 'service_lock' is held during all list traversals. This issue primarily affects local system stability and availability.
Affected products
- Linux Linux Kernel 3.17 to 6.12.96, 6.18.39, 7.1.4
Timeline
- 2026-07-25: advisory
- 2026-07-25: disclosed