CVE-2026-64529

Source
https://cve.org/CVERecord?id=CVE-2026-64529
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64529.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64529
Downstream
Published
2026-07-25T09:24:18.750Z
Modified
2026-07-28T04:03:13.685101274Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
crypto: qat - remove unused character device and IOCTLs
Details

In the Linux kernel, the following vulnerability has been resolved:

crypto: qat - remove unused character device and IOCTLs

The QAT driver exposes a character device (qatadfctl) with IOCTLs for device configuration, start, stop, status query and enumeration. These IOCTLs are not part of any public uAPI header and have no known in-tree or out-of-tree users. Device lifecycle is already managed via sysfs.

The ioctl interface also increases the attack surface and is the subject of a number of bug reports.

Remove the character device, the IOCTL definitions, and the related data structures (adfdevstatusinfo, adfusercfgkeyval, adfusercfgsection, adfusercfgctldata). Drop the now-unused adfcfguser.h header and strip adfctldrv.c down to the minimal moduleinit/moduleexit hooks for workqueue, AER, and crypto/compression algorithm registration.

Clean up leftover dead code that was only reachable from the removed IOCTL paths: adfcfgdelall(), adfdevmgrverifyid(), adfdevmgrgetnumdev(), adfdevmgrgetdevbyid(), adfgetvfrealid() and the unused ADFCFG macros.

Additionally, drop the entry associated to QAT IOCTLs in ioctl-number.rst.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64529.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
d8cba25d2c68992a6e7c1d329b690a9ebe01167d
Fixed
071590a44cbc38483fceb1ab943363ec26868e1b
Fixed
1de076f43e64bf65fbe7280a269c70e0e60518df
Fixed
a4999664a5ef77bdb0c6e6b935f581ac8ce6b63a
Fixed
6848a6e39cac44fdb7cb88f0f777df62172d1551
Fixed
b1ea97076bd0a5196290deba172034e480646727
Fixed
b8ebf008696de1ec08c90d51f94d7e40bd448be1
Fixed
de2cc38489b629927910b1aeff69bba7bd5c6f1b
Fixed
3ae49dd04dbb11fb73f17f58a982dba128abe83a
Fixed
d237230728c567297f2f98b425d63156ab2ed17f

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64529.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.17.0
Fixed
5.10.260
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.211
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.177
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.144
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.95
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.37
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.14
Type
ECOSYSTEM
Events
Introduced
7.1.0
Fixed
7.1.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64529.json"