Linux Kernel Vulnerability in QAT Driver Affecting Unused IOCTLs
CVE-2026-64529
What is CVE-2026-64529?
A vulnerability exists in the Linux kernel's QAT (QuickAssist Technology) driver that involves the exposure of a character device with IOCTLs designed for device management and status querying. These IOCTLs are not utilized in public APIs and have no known users, which increases the overall attack surface. Actions taken include the removal of the character device and associated IOCTLs, thus mitigating risks related to unused code and reducing the potential for exploitation. The patch not only strips away the unnecessary elements but also focuses on cleaning up related data structures and ensuring the module retains only essential functionalities. This change enhances the security posture of the kernel by addressing previously unmonitored pathways.
Affected Version(s)
Linux d8cba25d2c68992a6e7c1d329b690a9ebe01167d < 071590a44cbc38483fceb1ab943363ec26868e1b
Linux d8cba25d2c68992a6e7c1d329b690a9ebe01167d < 1de076f43e64bf65fbe7280a269c70e0e60518df
Linux d8cba25d2c68992a6e7c1d329b690a9ebe01167d