CVE-2026-64529
Linux Debian Analisi e mitigazione delle vulnerabilità

Panoramica

CVE-2026-64529 is a vulnerability in the Linux kernel's Intel QuickAssist Technology (QAT) driver (crypto: qat) stemming from an exposed, undocumented character device (qat_adf_ctl) with IOCTL interfaces that unnecessarily increase the kernel attack surface. The vulnerability affects Linux kernel versions from 3.17 up to (but not including) the patched stable releases. Fixed versions include 5.10.260, 5.15.211, 6.1.177, 6.6.144, 6.12.95, 6.18.37, 7.0.14, 7.1.2, and 7.2-rc1. It was published on July 25, 2026, with an estimated CVSS category of Medium and an EPSS score of approximately 0.0024 (GitHub Advisory, Feedly).

Dettagli tecnici

The root cause is the presence of an undocumented, unused IOCTL interface exposed via the qat_adf_ctl character device in the Linux kernel QAT (Quick Assist Technology) crypto driver. These IOCTLs — covering device configuration, start, stop, status query, and enumeration — are not part of any public uAPI header and have no known in-tree or out-of-tree users, yet they expand the kernel's local attack surface. The fix removes the character device entirely, along with associated data structures (adf_dev_status_info, adf_user_cfg_key_val, adf_user_cfg_section, adf_user_cfg_ctl_data), dead code functions (adf_cfg_del_all(), adf_devmgr_verify_id(), adf_devmgr_get_num_dev(), adf_devmgr_get_dev_by_id(), adf_get_vf_real_id()), and the adf_cfg_user.h header. This aligns with CWE-749 (Exposed Dangerous Method or Function) (GitHub Advisory).

Impatto

The exposed IOCTL interface provides a local attack surface that could be leveraged by a local user or process to interact with QAT device management functions in unintended ways, potentially leading to device misconfiguration, denial of service, or exploitation of bugs in the IOCTL handling code paths. The vulnerability is confined to systems with Intel QAT hardware and the affected kernel driver loaded. There is no evidence of remote exploitability; impact is limited to local privilege escalation or stability issues on affected hosts (GitHub Advisory, Feedly).

Mitigazione e soluzioni alternative

The fix has been merged upstream into multiple stable Linux kernel branches. Administrators should update to the following patched versions or later: 5.10.260, 5.15.211, 6.1.177, 6.6.144, 6.12.95, 6.18.37, 7.0.14, 7.1.2, or 7.2-rc1. As a workaround prior to patching, administrators can restrict access to the qat_adf_ctl character device via file permissions or remove/blacklist the QAT kernel module if the hardware is not in use. Device lifecycle management should be performed via sysfs as intended (GitHub Advisory, Feedly).

Risorse aggiuntive


FonteQuesto report è stato generato utilizzando l'intelligenza artificiale

Imparentato Linux Debian Vulnerabilità:

CVE ID

Severità

Punteggio

Tecnologie

Nome del componente

Exploit CISA KEV

Ha la correzione

Data di pubblicazione

CVE-2026-64530NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoJul 26, 2026
CVE-2024-14040NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoJul 26, 2026
CVE-2026-64529NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoJul 25, 2026
CVE-2026-64528NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoJul 25, 2026
CVE-2026-64527NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoJul 25, 2026

Valutazione gratuita delle vulnerabilità

Benchmark della tua posizione di sicurezza del cloud

Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.

Richiedi valutazione

Richiedi una demo personalizzata

Pronti a vedere Wiz in azione?

"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
David EstlickCISO (CISO)
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
Adam FletcherResponsabile della sicurezza
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."
Greg PoniatowskiResponsabile della gestione delle minacce e delle vulnerabilità