Junglewise Threat Intelligence

CVE-2026-74306: Linux kernel VFIO QAT race condition in qat_vf_resume_write

CVE-2026-74306 · Severity: high · CVSS 7.8 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's VFIO QAT driver (used for virtual machine access to Intel QAT accelerator hardware) contains a race condition in file position handling during VM migration state restoration. Two concurrent write operations could bypass buffer bounds checks and write beyond the allocated migration state buffer, causing memory corruption or a kernel crash that disrupts service availability.

Technical details

The vulnerability is a time-of-check-time-of-use (TOCTOU) race condition in the qat_vf_resume_write() function. The code checks the file position (filp->f_pos) boundary conditions before acquiring the migf->lock mutex, then re-reads f_pos under the lock for the actual copy operation. Concurrent writers can both pass the initial bounds check with an old offset value, then the second writer executes its copy after the first has advanced f_pos, writing past the end of the migration-state buffer. The fix moves the mutex lock acquisition before all boundary checks. This affects systems using VFIO QAT for VM migration with multiple concurrent write operations to the migration state device. The patch is available and has been committed to stable kernel releases.

Affected products

  • Linux Linux kernel Before 2026-06-10 (patch date)

Timeline

  • 2026-08-15: disclosed
  • 2026-06-10: patched: Patch committed by Alex Williamson

References

Related threats