Impact
The vulnerability involves the QAT reset worker in the Linux kernel queuing a SR‑IOV re‑enable work item that is stored on the stack. When the associated completion times out, the worker may return while the device_sriov_wq still holds or executes this stack‑backed work structure. If the stack frame unwinds before the work is cancelled, the work_struct can reference freed memory, leading to a use‑after‑free condition that can trigger a kernel panic or offer an avenue for escalating privileges.
Affected Systems
Products from the Linux kernel are affected. Versions of the kernel before the patch commit that introduced work cancellation on timeout are vulnerable; the exact release series is not specified in the data.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in CISA KEV, indicating a low probability of exploitation in the wild. However, because the flaw can cause a kernel crash, the potential impact is significant for affected systems. The risk remains for any system running an unpatched kernel variant that includes the vulnerable QAT code path.
OpenCVE Enrichment
Debian DLA
Debian DSA