Description
In the Linux kernel, the following vulnerability has been resolved:

crypto: qat - clear AES key schedule from stack

qat_alg_xts_reverse_key() expands the forward XTS AES key on the stack.
That schedule contains key material and can remain in the stack frame.

Clear the temporary crypto_aes_ctx with memzero_explicit() after the copy.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

The vulnerability resides in the QAT crypto subsystem of the Linux kernel, where the function qat_alg_xts_reverse_key expands an XTS AES key schedule onto the stack. The expanded key schedule contains sensitive key material that remains accessible in the caller's stack frame after the function returns, because it is not overwritten. This oversight can allow a local attacker who can read process memory to recover the AES key, leading to potential compromise of encrypted data and confidentiality violations. The weakness is a form of sensitive information exposure due to improper clearing of cryptographic key material (CWE‑200).

Affected Systems

The affected product is the Linux kernel itself. Vendors listed are Linux, Linux, implying all distributions that ship the upstream kernel. No specific version numbers are provided, so any deployment of the affected kernel code that has not yet incorporated the memzero_explicit fix is vulnerable. Version information is not specified in the submitted data.

Risk and Exploitability

The EPSS score is reported as less than 1 %, indicating a very low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, because the flaw permits disclosure of strong cryptographic keys, the potential impact remains high if the attack succeeds. The likely attack vector is local, requiring the attacker to access the stack memory of a running process or exploit a local privilege escalation that permits memory introspection. No publicly disclosed exploit is known.

Generated by OpenCVE AI on September 19, 2026 at 07:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a Linux kernel version that includes the memzero_explicit fix for qat_alg_xts_reverse_key.
  • If immediate kernel upgrade is not feasible, enable strict memory protection options such as CONFIG_STRICT_DEVMEM or other kernel hardening measures to restrict stack memory access.
  • If the distribution does not provide the updated kernel, rebuild or recompile the kernel with the patch applied.
  • Regularly review kernel security advisories and apply updates as soon as they are released.

Generated by OpenCVE AI on September 19, 2026 at 07:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: crypto: qat - clear AES key schedule from stack qat_alg_xts_reverse_key() expands the forward XTS AES key on the stack. That schedule contains key material and can remain in the stack frame. Clear the temporary crypto_aes_ctx with memzero_explicit() after the copy.
Title crypto: qat - clear AES key schedule from stack
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:55.212Z

Reserved: 2026-09-17T16:02:15.089Z

Link: CVE-2026-93161

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:11.533

Modified: 2026-09-17T17:18:11.533

Link: CVE-2026-93161

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T06:45:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor