Junglewise Threat Intelligence

CVE-2026-93162: Linux kernel QAT crypto use-after-free in SR-IOV reset

CVE-2026-93162 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's Intel QAT crypto accelerator driver contains a timing vulnerability in its SR-IOV (Single Root I/O Virtualization) reset handler. If a reset operation times out during virtual device re-enablement, the kernel can attempt to access or execute a work queue item backed by stack memory that is no longer valid, potentially causing memory corruption or system instability.

Technical details

This is a use-after-free vulnerability in the QAT (QuickAssist Technology) reset worker function (adf_device_reset_worker) in drivers/crypto/intel/qat/qat_common/adf_aer.c. The vulnerable code queues SR-IOV reenable work using a work_struct and completion that are embedded in a stack-allocated adf_sriov_dev_data structure. If the wait_for_completion_timeout() call expires before the work completes, the function returns while the device_sriov_wq workqueue still holds or is executing the stack-backed work item. After the stack frame unwinds, the workqueue may attempt to access freed stack memory. The fix adds cancel_work_sync() in the timeout path to ensure the work is cancelled before the stack frame exits. This affects all Linux kernel versions from the introduction of the vulnerable code (commit 4469f9b23468) through recent kernels. No known active exploitation in the wild has been reported.

Affected products

  • Linux Linux kernel affected versions from commit 4469f9b23468 onwards; patched in commit 455b0f3ac9e254edab9f5a873d337abe5e6e3604

Timeline

  • 2026-06-08: other: Fix commit authored by Giovanni Cabiddu
  • 2026-07-05: patched: Upstream commit 455b0f3ac9e254edab9f5a873d337abe5e6e3604 merged
  • 2026-09-17: disclosed: CVE-2026-93162 published

References

Related threats