SB2026072730 - Exposure of Resource to Wrong Sphere in Linux kernel qat qat_common driver



SB2026072730 - Exposure of Resource to Wrong Sphere in Linux kernel qat qat_common driver

Published: July 27, 2026

Security Bulletin ID SB2026072730
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Exposure of Resource to Wrong Sphere (CVE-ID: CVE-2026-64529)

CWE-ID: CWE-668 - Exposure of resource to wrong sphere

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to affect device configuration and control operations.

The vulnerability exists due to an exposed attack surface in the qat_adf_ctl character device and its ioctl interface when handling ioctl requests for device configuration, start, stop, status query, and enumeration. A local user can send crafted ioctl requests to affect device configuration and control operations.

The ioctl interface was not part of any public uAPI header.


Remediation

Install update from vendor's website.