CVE-2026-64529
CVE CVE-2026-64529EUVD EUVD-2026-49041Published 2026-07-25T09:24:18.000ZLast changed 2026-08-05T12:42:38.000ZCVSS 7.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: crypto: qat - remove unused character device and IOCTLs The QAT driver exposes a character device (qat_adf_ctl) with IOCTLs for device configuration, start, stop, status query and enumeration. These IOCTLs are not part of any public uAPI header and have no known in-tree or out-of-tree users. Device lifecycle is already managed via sysfs. The ioctl interface also increases the attack surface and is the subject of a number of bug reports. Remove the character device, the IOCTL definitions, and the related data structures (adf_dev_status_info, adf_user_cfg_key_val, adf_user_cfg_section, adf_user_cfg_ctl_data). Drop the now-unused adf_cfg_user.h header and strip adf_ctl_drv.c down to the minimal module_init/module_exit hooks for workqueue, AER, and crypto/compression algorithm registration. Clean up leftover dead code that was only reachable from the removed IOCTL paths: adf_cfg_del_all(), adf_devmgr_verify_id(), adf_devmgr_get_num_dev(), adf_devmgr_get_dev_by_id(), adf_get_vf_real_id() and the unused ADF_CFG macros. Additionally, drop the entry associated to QAT IOCTLs in ioctl-number.rst.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 7.1.2; 3.17; d8cba25d2c68992a6e7c1d329b690a9ebe01167d <071590a44cbc38483fceb1ab943363ec26868e1b; patch: 7.2-rc1; patch: 6.1.177; d8cba25d2c68992a6e7c1d329b690a9ebe01167d <b1ea97076bd0a5196290deba172034e480646727; d8cba25d2c68992a6e7c1d329b690a9ebe01167d <3ae49dd04dbb11fb73f17f58a982dba128abe83a; d8cba25d2c68992a6e7c1d329b690a9ebe01167d <b8ebf008696de1ec08c90d51f94d7e40bd448be1; d8cba25d2c68992a6e7c1d329b690a9ebe01167d <a4999664a5ef77bdb0c6e6b935f581ac8ce6b63a; patch: 6.12.95; patch: 6.18.37; d8cba25d2c68992a6e7c1d329b690a9ebe01167d <de2cc38489b629927910b1aeff69bba7bd5c6f1b; patch: 5.15.211; patch: 0; d8cba25d2c68992a6e7c1d329b690a9ebe01167d <6848a6e39cac44fdb7cb88f0f777df62172d1551; d8cba25d2c68992a6e7c1d329b690a9ebe01167d <d237230728c567297f2f98b425d63156ab2ed17f; patch: 6.6.144; d8cba25d2c68992a6e7c1d329b690a9ebe01167d <1de076f43e64bf65fbe7280a269c70e0e60518df; patch: 5.10.260; patch: 7.0.14
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.