Description
In the Linux kernel, the following vulnerability has been resolved:

crypto: qat - cancel work on re-enable SR-IOV timeout

The QAT reset worker queues SR-IOV reenable work using a work_struct and
completion embedded in an on-stack adf_sriov_dev_data. If the completion
wait times out, the reset worker can return while device_sriov_wq still
holds or executes the stack-backed work item.

Cancel the work on the device_sriov_wq on timeout before the stack frame
unwinds.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (kernel crash)
Action: Apply patch
AI Analysis

Impact

The vulnerability involves the QAT reset worker in the Linux kernel queuing a SR‑IOV re‑enable work item that is stored on the stack. When the associated completion times out, the worker may return while the device_sriov_wq still holds or executes this stack‑backed work structure. If the stack frame unwinds before the work is cancelled, the work_struct can reference freed memory, leading to a use‑after‑free condition that can trigger a kernel panic or offer an avenue for escalating privileges.

Affected Systems

Products from the Linux kernel are affected. Versions of the kernel before the patch commit that introduced work cancellation on timeout are vulnerable; the exact release series is not specified in the data.

Risk and Exploitability

The EPSS score is below 1 % and the vulnerability is not listed in CISA KEV, indicating a low probability of exploitation in the wild. However, because the flaw can cause a kernel crash, the potential impact is significant for affected systems. The risk remains for any system running an unpatched kernel variant that includes the vulnerable QAT code path.

Generated by OpenCVE AI on September 19, 2026 at 07:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a Linux kernel version that includes the QAT patch for canceling SR‑IOV re‑enable work on timeout
  • If updating the kernel is not immediately possible, apply the upstream patch provided by the maintainers to ensure work cancellation logic is exercised
  • Disable SR‑IOV on QAT devices if the functionality is not required, thereby eliminating the vulnerable code path
  • Monitor system logs for any indications of work timeout or kernel panics related to SR‑IOV operations

Generated by OpenCVE AI on September 19, 2026 at 07:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: crypto: qat - cancel work on re-enable SR-IOV timeout The QAT reset worker queues SR-IOV reenable work using a work_struct and completion embedded in an on-stack adf_sriov_dev_data. If the completion wait times out, the reset worker can return while device_sriov_wq still holds or executes the stack-backed work item. Cancel the work on the device_sriov_wq on timeout before the stack frame unwinds.
Title crypto: qat - cancel work on re-enable SR-IOV timeout
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:55.896Z

Reserved: 2026-09-17T16:02:15.089Z

Link: CVE-2026-93162

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:11.657

Modified: 2026-09-17T17:18:11.657

Link: CVE-2026-93162

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T17:30:07Z

Weaknesses