PT-2026-64659 · Linux · Linux

CVE-2026-64438

·

Publicado

2026-07-25

·

Atualizado

2026-07-25

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
crypto: qat - fix VF2PF work teardown race in adf disable sriov()
The VF2PF interrupt handler queues PF-side response work that stores a raw pointer to per-VF state (struct adf accel vf info). Currently, adf disable sriov() destroys per-VF mutexes and frees vf info without stopping new VF2PF work or waiting for in-flight workers to complete. A concurrently scheduled or already queued worker can then dereference freed memory.
This manifests as a use-after-free when KASAN is enabled:
BUG: KASAN: null-ptr-deref in mutex lock+0x76/0xe0 Write of size 8 at addr 0000000000000260 by task kworker/24:2/... Workqueue: qat pf2vf resp wq adf iov send resp [intel qat] Call Trace: kasan report+0x119/0x140 mutex lock+0x76/0xe0 adf gen4 pfvf send+0xd4/0x1f0 [intel qat] adf recv and handle vf2pf msg+0x290/0x360 [intel qat] adf iov send resp+0x8c/0xe0 [intel qat] process one work+0x6ac/0xfd0 worker thread+0x4dd/0xd30 kthread+0x326/0x410 ret from fork+0x33b/0x670
Add a PF-local flag, vf2pf disabled, that gates work queueing, worker processing, and interrupt re-enabling during teardown. Set this flag atomically with the hardware interrupt mask inside adf disable all vf2pf interrupts(). After masking, synchronize the AE cluster MSI-X interrupt and flush the PF response workqueue before tearing down per-VF locks and state so all in-flight work completes before vf info is destroyed.
Introduce adf enable all vf2pf interrupts() to clear the flag and unmask all VF2PF interrupts under the same lock when SR-IOV is re-enabled. This ensures the software flag and hardware state transition atomically on both the enable and disable paths.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-64438

Produtos afetados

Linux