CVE-2025-35998
Linux Red Hat vulnerability analysis and mitigation

Overview

CVE-2025-35998 is a privilege escalation vulnerability caused by a missing protection mechanism for an alternate hardware interface in Intel® Quick Assist Technology (QAT) on certain Intel® platforms. The flaw exists within Ring 0 (kernel level) and can be exploited by a local attacker with high privileges to escalate privileges and compromise system confidentiality and integrity. It was published on February 10, 2026, with Intel's advisory INTEL-SA-01406 released the same day. The vulnerability carries a CVSS v3.1 base score of 7.9 (High) and a CVSS v4.0 base score of 7.0 (High) (Intel Advisory).

Technical details

The root cause is classified as CWE-1299 (Missing Protection Mechanism for Alternate Hardware Interface), meaning the Intel QAT hardware exposes an alternate interface that lacks adequate access controls at the kernel (Ring 0) level. An attacker with existing high-privileged (kernel-level) access and special internal knowledge of the hardware interface can exploit this flaw locally, with low attack complexity and no user interaction required. Attack requirements (AT:P) must be present, indicating specific preconditions such as a particular system configuration or hardware state. No public proof-of-concept or technical write-up has been identified at this time (Intel Advisory).

Impact

Successful exploitation allows a privileged local attacker to escalate privileges beyond their current access level, resulting in high confidentiality and high integrity impact on the vulnerable system. Availability is not directly impacted. The changed scope (S:C in CVSS v3.1) indicates the vulnerability can affect resources beyond the component itself, potentially enabling access to sensitive kernel-level data or manipulation of system integrity across security boundaries (Intel Advisory).

Mitigation and workarounds

Intel has released a patch addressing CVE-2025-35998 as documented in advisory INTEL-SA-01406 (published February 10, 2026). Affected users should update their Intel® Quick Assist Technology software/firmware to the fixed version specified in the advisory. Red Hat has also issued an errata (RHSA-2026:6888) for affected Linux distributions. Organizations should prioritize applying vendor-supplied updates and restrict local privileged access to systems running Intel QAT to reduce exposure (Intel Advisory, Red Hat Errata).

Additional resources


SourceThis report was generated using AI

Related Linux Red Hat vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-66758HIGH7.8
  • Linux Debian logoLinux Debian
  • gimp:2.8::pygtk2
NoNoJul 27, 2026
CVE-2026-17523HIGH7.8
  • Linux Kernel logoLinux Kernel
  • kernel-modules
NoNoJul 27, 2026
CVE-2026-66759HIGH7.1
  • Linux Debian logoLinux Debian
  • gimp-devel-tools
NoNoJul 27, 2026
CVE-2026-15003MEDIUM5.6
  • Linux Red Hat logoLinux Red Hat
  • gcc-toolset-14-binutils-gprofng
NoNoJul 27, 2026
CVE-2026-66757MEDIUM5.5
  • Linux Debian logoLinux Debian
  • gimp:2.8::pygtk2
NoNoJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management