Exposure of Resource to Wrong Sphere in Linux kernel - CVE-2026-64529
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to affect device configuration and control operations.
The vulnerability exists due to an exposed attack surface in the qat_adf_ctl character device and its ioctl interface when handling ioctl requests for device configuration, start, stop, status query, and enumeration. A local user can send crafted ioctl requests to affect device configuration and control operations.
The ioctl interface was not part of any public uAPI header.
Affected software
How to mitigate CVE-2026-64529
External References
- https://git.kernel.org/stable/c/071590a44cbc38483fceb1ab943363ec26868e1b
- https://git.kernel.org/stable/c/1de076f43e64bf65fbe7280a269c70e0e60518df
- https://git.kernel.org/stable/c/3ae49dd04dbb11fb73f17f58a982dba128abe83a
- https://git.kernel.org/stable/c/6848a6e39cac44fdb7cb88f0f777df62172d1551
- https://git.kernel.org/stable/c/a4999664a5ef77bdb0c6e6b935f581ac8ce6b63a
- https://git.kernel.org/stable/c/b1ea97076bd0a5196290deba172034e480646727
- https://git.kernel.org/stable/c/b8ebf008696de1ec08c90d51f94d7e40bd448be1
- https://git.kernel.org/stable/c/d237230728c567297f2f98b425d63156ab2ed17f
- https://git.kernel.org/stable/c/de2cc38489b629927910b1aeff69bba7bd5c6f1b