Description
In the Linux kernel, the following vulnerability has been resolved:

vfio/qat: fix f_pos race in qat_vf_resume_write()

qat_vf_resume_write() checks filp->f_pos before taking migf->lock, but
copies into the migration-state buffer after taking the lock and
re-reading the shared file position.

Two concurrent writers could therefore pass the bounds check with the
old offset, then have the second writer copy after the first advanced
f_pos, writing past the end of the migration-state buffer.

Take migf->lock before doing the boundary checks.
Published: 2026-08-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability originates from a race condition in the vfio/qat driver’s qat_vf_resume_write() function. Two concurrent writers may each read the file position before obtaining the migration‑state lock, then both copy data after the lock is taken, causing an out‑of‑bounds write into the migration‑state buffer. This memory corruption can overwrite kernel structures, potentially leading to a crash or enabling an attacker to execute code in kernel mode. The flaw is a classic buffer overflow triggered by write operations that the driver fails to guard against.

Affected Systems

The defect resides exclusively in the Linux kernel’s vfio/qat driver. No specific kernel release numbers are listed in the advisory, so every kernel version that ships the vulnerable driver segment is potentially affected until a patched version is deployed. The affected fabric is all Linux distributions running the susceptible Linux kernel with the vfio/qat module active.

Risk and Exploitability

The CVSS score of 7.8 indicates a moderate‑to‑high severity for local privilege escalation. The EPSS score of <1% suggests a very low probability of exploitation but is not zero, implying that while the vulnerability is not widely seized by attackers yet, it remains a relevant concern in environments where many users can access the QAT device. The flaw is not listed in CISA’s KEV catalog, so no active exploit advisories are known. In practice, an attacker who can orchestrate concurrent writes to the QAT interface could trigger the race, leading to kernel memory corruption and potentially arbitrary code execution as the kernel. The likely attack vector is concurrent writes, which an attacker can generate if they have write permissions on the QAT device.

Generated by OpenCVE AI on August 22, 2026 at 02:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a Linux kernel update that includes the latest vfio/qat driver patch (commit 4ec5e932e636896e97e4c6a8205b0ac76d52421a or later).
  • If you cannot apply the update immediately, unload or disable the vfio/qat kernel module or the QAT device driver to block access to the vulnerable interface.
  • Restrict access to the QAT device by tightening file permissions or using device cgroups so that only trusted users can write to the device.

Generated by OpenCVE AI on August 22, 2026 at 02:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
CWE-368

Fri, 21 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 17 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
CWE-368

Mon, 17 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
CWE-787

Mon, 17 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 15 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
CWE-787

Sat, 15 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: vfio/qat: fix f_pos race in qat_vf_resume_write() qat_vf_resume_write() checks filp->f_pos before taking migf->lock, but copies into the migration-state buffer after taking the lock and re-reading the shared file position. Two concurrent writers could therefore pass the bounds check with the old offset, then have the second writer copy after the first advanced f_pos, writing past the end of the migration-state buffer. Take migf->lock before doing the boundary checks.
Title vfio/qat: fix f_pos race in qat_vf_resume_write()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:45:40.501Z

Reserved: 2026-08-15T05:44:03.883Z

Link: CVE-2026-74306

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:22:30.357

Modified: 2026-08-17T06:19:24.793

Link: CVE-2026-74306

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-74306 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T02:45:03Z

Weaknesses