External risk intelligence

Linux Kernel Crypto IAA Unmaps DMA Before Software Fallback Corruption.

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-80945

This vulnerability exists within a specific low-level Linux kernel cryptographic driver (IAA - Intel Analytics Accelerator). It is a deep internal kernel component handling DMA memory mapping and hardware-to-software fallback mechanisms, not a service or interface exposed to the network or accessible by external users.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a critical vulnerability within the Linux kernel's cryptographic acceleration module. It concerns how data is unmapped before a software fallback occurs during decompression, which could lead to data corruption if a hardware error happens. The main concern at this time is confirming the relevance and exposure of this specific kernel component within our environment.

  • Data corruption in Linux kernel crypto driver.
  • Leadership should remember potential for data integrity issues.
  • Confirm relevance and exposure of this specific component.

Attack Path

How an attacker could exploit the issue

An attacker could trigger this vulnerability by causing a hardware analytics error within the Linux kernel's crypto subsystem. This error would lead to a software fallback for decompression, which, under specific conditions involving DMA memory mapping, could result in corrupted data.

  • Requires hardware analytics error for triggering.
  • Vulnerable component: Linux kernel crypto decompression.
  • Risk: Data corruption.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could affect system data integrity when the Linux kernel's Intel Analytics Accelerator (IAA) driver encounters a hardware analytics error during decompression. When this occurs, the system may attempt a software fallback, potentially corrupting data by writing to a memory buffer that is still mapped for DMA from a device.

  • System data integrity.
  • Data corruption during decompression fallback.
  • Compromised data accuracy.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability resides within the Linux kernel's Intel Analytics Accelerator (IAA) cryptographic driver. Responsibility for addressing this issue likely falls to the infrastructure or platform teams managing the underlying Linux systems where this hardware acceleration is utilized. The immediate first step should be to identify all systems employing the IAA hardware, determine if the affected driver path is in use, and assess business criticality before planning any necessary remediation.

  • Infrastructure or platform teams own the fix.
  • Verify IAA hardware usage and driver path.
  • Plan remediation around maintenance windows.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the IAA driver in the Linux kernel?

The IAA (Intel Analytics Accelerator) driver is a specialized component within the Linux kernel designed to offload data decompression tasks to dedicated hardware. It helps improve system performance for high-speed data processing. This vulnerability specifically affects how this driver handles memory during rare hardware analytics errors.

What kind of vulnerability is CVE-2026-80945?

This is a memory management issue related to Direct Memory Access (DMA). When the hardware encounters an error, the system tries to switch to a software-based fallback for decompression. Because the memory is not unmapped correctly beforehand, the hardware and software pathways conflict, leading to data corruption.

How can this vulnerability be triggered?

The flaw is triggered only when the IAA hardware experiences an analytics error during a decompression operation. If the hardware is functioning normally, the error path is not taken, and the corruption does not occur. It requires this specific failure sequence to impact the data buffer.

Is my system at risk for this issue?

According to Halo Surface Signal, this is very unlikely. The vulnerability exists deep within a specific, low-level kernel driver that is not exposed to the network or external users. It is an internal component that does not provide a direct interface for remote attackers to interact with.

What should I do if I run systems with IAA hardware?

Your infrastructure or platform team should first confirm if your systems are actively using the IAA driver path. If they are, treat this as a data integrity maintenance task. Identify the affected hardware, assess its business importance, and coordinate with your internal teams to plan updates during standard maintenance windows.

References