Exposure of Resource to Wrong Sphere in Linux kernel - CVE-2026-64529

 

Exposure of Resource to Wrong Sphere in Linux kernel - CVE-2026-64529

Published: July 27, 2026


Vulnerability identifier: #VU139407
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-64529
CWE-ID: CWE-668
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to affect device configuration and control operations.

The vulnerability exists due to an exposed attack surface in the qat_adf_ctl character device and its ioctl interface when handling ioctl requests for device configuration, start, stop, status query, and enumeration. A local user can send crafted ioctl requests to affect device configuration and control operations.

The ioctl interface was not part of any public uAPI header.


Affected software

Linux kernel

How to mitigate CVE-2026-64529

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins