Database/Control plane, storage & DevOps
Intel QuickAssist Technology (QAT) software and drivers
Impact
Out-of-bounds write in the QAT software stack giving an authenticated local user privilege escalation, with a further improper-input-validation escalation (CVSS 8.8) in the 2025 batch and an earlier credential-exposure issue in the Linux QAT package. QAT is the crypto and compression offload engine on Xeon platforms - it terminates TLS and does bulk compression for storage paths, so it handles key material by design, and it is a DMA-capable PCIe device. A local escalation through the QAT driver is a container-to-root path on nodes where QAT is enabled, and QAT's position in the TLS path makes credential exposure in the same stack materially worse than a generic driver bug.
Who can reach it
Authenticated local user on the host with access to the QAT device interfaces. Where QAT is exposed into containers or VMs for offload, that is the tenant.
What to do
Update the QAT driver and software package to 2.2.0 or later (2.6.0+ for the 2025 batch) - a software/driver update from Intel, not a firmware flash, so it can go out with a service restart or reboot rather than a full firmware maintenance window. If QAT is not actually in use on a node, unbind and blacklist the driver rather than leaving an unused DMA-capable offload path exposed to tenants. Where you do expose QAT to tenants, review whether the crypto offload path is carrying keys that a tenant-side escalation would reach.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.