CVE-2026-93162

Summary

In the Linux kernel, the following vulnerability has been resolved:

crypto: qat - cancel work on re-enable SR-IOV timeout

The QAT reset worker queues SR-IOV reenable work using a work_struct and completion embedded in an on-stack adf_sriov_dev_data. If the completion wait times out, the reset worker can return while device_sriov_wq still holds or executes the stack-backed work item.

Cancel the work on the device_sriov_wq on timeout before the stack frame unwinds.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux4469f9b2346834085fe4478ee1a851ee1de8ccb2 < cbeef7ba0de4a7b84a772eee1784948473e7a7e6affected
LinuxLinux4469f9b2346834085fe4478ee1a851ee1de8ccb2 < 6b19f343ae8ada4c84209bc6f62d50ea9781c4aeaffected
LinuxLinux4469f9b2346834085fe4478ee1a851ee1de8ccb2 < 1a106c6e17525827ee6d8091bb8c06fafbc21fedaffected
LinuxLinux4469f9b2346834085fe4478ee1a851ee1de8ccb2 < 455b0f3ac9e254edab9f5a873d337abe5e6e3604affected
LinuxLinux6.9affected
LinuxLinux0 < 6.9unaffected
LinuxLinux6.12.110 <= 6.12.*unaffected
LinuxLinux6.18.52 <= 6.18.*unaffected
LinuxLinux7.2.6 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References