Impact
The vulnerability resides in the QAT crypto subsystem of the Linux kernel, where the function qat_alg_xts_reverse_key expands an XTS AES key schedule onto the stack. The expanded key schedule contains sensitive key material that remains accessible in the caller's stack frame after the function returns, because it is not overwritten. This oversight can allow a local attacker who can read process memory to recover the AES key, leading to potential compromise of encrypted data and confidentiality violations. The weakness is a form of sensitive information exposure due to improper clearing of cryptographic key material (CWE‑200).
Affected Systems
The affected product is the Linux kernel itself. Vendors listed are Linux, Linux, implying all distributions that ship the upstream kernel. No specific version numbers are provided, so any deployment of the affected kernel code that has not yet incorporated the memzero_explicit fix is vulnerable. Version information is not specified in the submitted data.
Risk and Exploitability
The EPSS score is reported as less than 1 %, indicating a very low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, because the flaw permits disclosure of strong cryptographic keys, the potential impact remains high if the attack succeeds. The likely attack vector is local, requiring the attacker to access the stack memory of a running process or exploit a local privilege escalation that permits memory introspection. No publicly disclosed exploit is known.
OpenCVE Enrichment
Debian DLA
Debian DSA