Database/Kernel, userspace & hypervisor
Linux kernel (drivers/vfio/pci/qat): Two concurrent writes to the QAT VF migration-resume file both pass the bounds
Impact
Two concurrent writes to the QAT VF migration-resume file both pass the bounds check against a stale file offset, then copy past the end of the kernel migration-state buffer. Whoever can write that fd gets a controlled kernel heap overflow with attacker-supplied bytes - a straightforward path from a device-holder to host privilege.
Who can reach it
Whoever holds the vfio migration file descriptor for a QAT VF: the VMM restoring a migrated guest, or a tenant handed the device directly. Two threads writing the fd concurrently is the whole exploit. Conditional on the qat_vfio_pci variant driver being bound to an Intel QuickAssist VF - not reachable on nodes that do not pass through QAT VFs.
What to do
Update to a stable kernel carrying commits 6465af00 / d416dcef. Interim: if you do not live-migrate QAT VFs, bind them to plain vfio-pci instead of qat_vfio_pci, or stop passing QAT VFs to tenants until the kernel is patched.
References
Related entries
- Linux kernel BPF: BPF_PROG_QUERY writes the revision field past a short bpf_attr from userspaceCVE-2026-74371 · Linux kernel BPF BPF_PROG_QUERY (cgroup query revision write-back)High
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A race condition or locking defect in the amdkfd (KFDCVE-2026-74446 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)High
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): An out-of-bounds access in the amdkfd (KFD computeCVE-2026-74447 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)High
- Linux kernel THP split: use-after-free on the inode when memory-failure splits a shmem huge pageCVE-2026-74482 · Linux kernel mm/huge_memory (__folio_split i_mmap_rwsem release order)High
- Linux kernel hugetlbfs: list corruption in reservation top-up can link a kernel-stack address into MM stateCVE-2026-74518 · Linux kernel hugetlbfs reservation map (allocate_file_region_entries)High
- Linux kernel (net/rds): Bind() on an RDS socket with a scoped IPv6 address looks up the interface under RCU, drops theCVE-2026-74563 · Linux kernel (net/rds)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.