Junglewise Threat Intelligence

CVE-2026-64438: Linux Kernel Intel QAT use-after-free in adf_disable_sriov

CVE-2026-64438 · Severity: info · CVSS 5.5 · Published 2026-07-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Intel QuickAssist Technology (QAT) driver. The issue occurs when the system disables certain virtualization features (SR-IOV), potentially causing the system to crash or behave unpredictably due to a race condition in memory handling. This could lead to a denial of service, impacting the availability of systems using QAT hardware for cryptographic acceleration.

Technical details

A use-after-free vulnerability exists in the Intel QAT driver (crypto: qat) within the adf_disable_sriov() function. The VF2PF (Virtual Function to Physical Function) interrupt handler queues work that maintains a raw pointer to per-VF state. When SR-IOV is disabled, the driver destroys per-VF mutexes and frees the vf_info structure without ensuring that in-flight workqueue items have completed. A concurrently scheduled worker can then dereference this freed memory, leading to a kernel BUG (null-ptr-deref or KASAN splat). The fix introduces a synchronization flag and flushes the response workqueue before state teardown.

Affected products

  • Linux Linux Kernel ed8ccaef52fa to 218c2836b3987f3fa1d9eac505462cded0821e4c

Timeline

  • 2026-07-15: other: Patch authored
  • 2026-07-24: patched: Patch committed to stable tree
  • 2026-07-25: disclosed: CVE published

References

Related threats