Database/Control plane, storage & DevOps
Intel QuickAssist Technology (QAT) software and drivers
Impact
Out-of-bounds write in the QAT software stack giving an authenticated local user privilege escalation, with a further improper-input-validation escalation (CVSS 8.8) in the 2025 batch and an earlier credential-exposure issue in the Linux QAT package. QAT is the crypto and compression offload engine on Xeon platforms - it terminates TLS and does bulk compression for storage paths, so it handles key material by design, and it is a DMA-capable PCIe device. A local escalation through the QAT driver is a container-to-root path on nodes where QAT is enabled, and QAT's position in the TLS path makes credential exposure in the same stack materially worse than a generic driver bug.
Who can reach it
Authenticated local user on the host with access to the QAT device interfaces. Where QAT is exposed into containers or VMs for offload, that is the tenant.
What to do
Update the QAT driver and software package to 2.2.0 or later (2.6.0+ for the 2025 batch) - a software/driver update from Intel, not a firmware flash, so it can go out with a service restart or reboot rather than a full firmware maintenance window. If QAT is not actually in use on a node, unbind and blacklist the driver rather than leaving an unused DMA-capable offload path exposed to tenants. Where you do expose QAT to tenants, review whether the crypto offload path is carrying keys that a tenant-side escalation would reach.
References
Related entries
- IBM Storage Scale GUI (local privilege escalation): A local privilege escalation in the Storage Scale GUI availableCVE-2024-31891 · IBM Storage Scale GUI (local privilege escalation)High
- Linux HID/amd_sfh - driver_data freed after HID device destruction: A use-after-free in the AMD Sensor Fusion Hub HIDCVE-2024-46746 · Linux HID/amd_sfh - driver_data freed after HID device destructionHigh
- N-able N-central: Deserialization of untrusted data allowing local code execution on the RMM serverCVE-2025-8875 · N-able N-centralHigh
- ansible-core: malicious Galaxy role injects git flags to run code on the machine installing itCVE-2026-11332 · ansible-core (ansible-galaxy role install, git argument injection via meta/requirements.yml)High
- ansible-core: git argument injection in ansible-galaxy collection install yields command executionCVE-2026-16493 · ansible-core (ansible-galaxy collection install, git source URL handling)High
- MUNGE (munged credential daemon): This is the root of trust under Slurm. A crafted message with an oversizedCVE-2026-25506 · MUNGE (munged credential daemon)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.