Answer in brief
CVE-2026-64304 records a Unknown severity vulnerability in crypto: qat - validate RSA CRT component lengths. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-64304 records a Unknown severity vulnerability in crypto: qat - validate RSA CRT component lengths. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=879f77e9071f029e1c9bd5a75814ecf51370f846 <6d99c5fadd2df488103f64d6475b63ba6852202b || >=879f77e9071f029e1c9bd5a75814ecf51370f846 <c34369473bfe92a0b46ec78d6358e30341c7f481 || >=879f77e9071f029e1c9bd5a75814ecf51370f846 <1002719d13072a5e4be1e993aa61dffb4a604e82 || >=879f77e9071f029e1c9bd5a75814ecf51370f846 <500319830d76911c120dc0b9605f8c16d7702844 || >=879f77e9071f029e1c9bd5a75814ecf51370f846 <3d61a214fdcda41f1ebfabbb483404032a7b4d91 || >=879f77e9071f029e1c9bd5a75814ecf51370f846 <6fb62b767f3e27661e8f8d2f7b85f4e098fcdb1a || >=879f77e9071f029e1c9bd5a75814ecf51370f846 <ce42224487c504aee4b7ff3a7342e7b4d7e28cc9 || >=879f77e9071f029e1c9bd5a75814ecf51370f846 <b3ac78756588059729b9195fcc9f4b37d54057a5 | 6d99c5fadd2df488103f64d6475b63ba6852202b, c34369473bfe92a0b46ec78d6358e30341c7f481, 1002719d13072a5e4be1e993aa61dffb4a604e82, 500319830d76911c120dc0b9605f8c16d7702844, 3d61a214fdcda41f1ebfabbb483404032a7b4d91, 6fb62b767f3e27661e8f8d2f7b85f4e098fcdb1a, ce42224487c504aee4b7ff3a7342e7b4d7e28cc9, b3ac78756588059729b9195fcc9f4b37d54057a5 |
| Linux/Linuxgeneric | 4.8 | Not reported |
Published upstream
Jul 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: crypto: qat - validate RSA CRT component lengths The generic RSA key parser (rsa_helper.c) bounds each CRT component (p, q, dp, dq, qinv) by the modulus size n_sz, but qat_rsa_setkey_crt() allocates half-size DMA buffers (key_sz / 2) and right-aligns each component with: memcpy(dst + half_key_sz - len, src, len) When a CRT component is larger than half_key_sz the subtraction underflows and memcpy writes past the DMA buffer, causing memory corruption. Add a len > half_key_sz check next to the existing !len check for each of the five CRT components so the driver falls back to the non-CRT path instead of writing out of bounds.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=879f77e9071f029e1c9bd5a75814ecf51370f846 <6d99c5fadd2df488103f64d6475b63ba6852202b || >=879f77e9071f029e1c9bd5a75814ecf51370f846 <c34369473bfe92a0b46ec78d6358e30341c7f481 || >=879f77e9071f029e1c9bd5a75814ecf51370f846 <1002719d13072a5e4be1e993aa61dffb4a604e82 || >=879f77e9071f029e1c9bd5a75814ecf51370f846 <500319830d76911c120dc0b9605f8c16d7702844 || >=879f77e9071f029e1c9bd5a75814ecf51370f846 <3d61a214fdcda41f1ebfabbb483404032a7b4d91 || >=879f77e9071f029e1c9bd5a75814ecf51370f846 <6fb62b767f3e27661e8f8d2f7b85f4e098fcdb1a || >=879f77e9071f029e1c9bd5a75814ecf51370f846 <ce42224487c504aee4b7ff3a7342e7b4d7e28cc9 || >=879f77e9071f029e1c9bd5a75814ecf51370f846 <b3ac78756588059729b9195fcc9f4b37d54057a5 | 6d99c5fadd2df488103f64d6475b63ba6852202b, c34369473bfe92a0b46ec78d6358e30341c7f481, 1002719d13072a5e4be1e993aa61dffb4a604e82, 500319830d76911c120dc0b9605f8c16d7702844, 3d61a214fdcda41f1ebfabbb483404032a7b4d91, 6fb62b767f3e27661e8f8d2f7b85f4e098fcdb1a, ce42224487c504aee4b7ff3a7342e7b4d7e28cc9, b3ac78756588059729b9195fcc9f4b37d54057a5 |
| Linux/Linuxgeneric | 4.8 | Not reported |
Published upstream
Jul 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: crypto: qat - validate RSA CRT component lengths The generic RSA key parser (rsa_helper.c) bounds each CRT component (p, q, dp, dq, qinv) by the modulus size n_sz, but qat_rsa_setkey_crt() allocates half-size DMA buffers (key_sz / 2) and right-aligns each component with: memcpy(dst + half_key_sz - len, src, len) When a CRT component is larger than half_key_sz the subtraction underflows and memcpy writes past the DMA buffer, causing memory corruption. Add a len > half_key_sz check next to the existing !len check for each of the five CRT components so the driver falls back to the non-CRT path instead of writing out of bounds.
Quoted source text, attributed separately from HOL analysis.