Executive brief
A vulnerability was identified in the Linux kernel's Intel QuickAssist Technology (QAT) driver. The issue occurs when the system disables certain virtualization features (SR-IOV), potentially causing the system to crash or behave unpredictably due to a race condition in memory handling. This could lead to a denial of service, impacting the availability of systems using QAT hardware for cryptographic acceleration.
Technical details
A use-after-free vulnerability exists in the Intel QAT driver (crypto: qat) within the adf_disable_sriov() function. The VF2PF (Virtual Function to Physical Function) interrupt handler queues work that maintains a raw pointer to per-VF state. When SR-IOV is disabled, the driver destroys per-VF mutexes and frees the vf_info structure without ensuring that in-flight workqueue items have completed. A concurrently scheduled worker can then dereference this freed memory, leading to a kernel BUG (null-ptr-deref or KASAN splat). The fix introduces a synchronization flag and flushes the response workqueue before state teardown.
Affected products
- Linux Linux Kernel ed8ccaef52fa to 218c2836b3987f3fa1d9eac505462cded0821e4c
Timeline
- 2026-07-15: other: Patch authored
- 2026-07-24: patched: Patch committed to stable tree
- 2026-07-25: disclosed: CVE published
References
- https://git.kernel.org/stable/c/218c2836b3987f3fa1d9eac505462cded0821e4c
- https://git.kernel.org/stable/c/277281c10c63791067d24d421f7c43a15faa9096
- https://git.kernel.org/stable/c/446b4d77599cf1a168573f7fb32a4a6aa4f09219
- https://git.kernel.org/stable/c/49cd5ac6de8de39a14ead609bb552d372d5602cd
- https://git.kernel.org/stable/c/51144032248cc4ea22917370565650670b8b4e9b
- https://git.kernel.org/stable/c/5d916c1eae1933511a69bffe243b4ee5d7da399c
- https://git.kernel.org/stable/c/6e92b28cd74fa433658efeadf21b9d4b01023d7d