Impact
A race between the VF‑to‑PF interrupt handler and the SR‑IOV teardown routine in the Linux intel_qat driver causes the driver to free per‑VF structures before queued work has finished. The resulting use‑after‑free can lead to a kernel panic or, if memory is overwritten, arbitrary code execution. This flaw falls under CWE‑416 and CWE‑825.
Affected Systems
All versions of the Linux kernel that ship the intel_qat driver prior to the patch are affected. The issue manifests when SR‑IOV is enabled and workers are queued in the qat_pf2vf_resp_wq workqueue.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. The EPSS score of less than 1 % reflects a low present exploitation probability, and the vulnerability is not listed in CISA KEV. Based on the description, it is inferred that the attack vector requires local or privileged access that allows toggling SR‑IOV or injecting crafted VF‑to‑PF messages from a virtual machine or host. An attacker with such access could trigger the race, causing a denial of service or potentially gaining kernel‑level execution.
OpenCVE Enrichment
Debian DLA
Debian DSA