Intel® QuickAssist Technology (QAT) Provider
Intel® QuickAssist Technology (QAT) Provider, from Intel Corporation, holds FIPS 140-3 certificate #5032 at overall level 1. The validation is active, with a sunset date of 2030-06-25. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.
Caveat: No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs
Certificate
| Certificate number | 5032 |
|---|---|
| Standard | FIPS 140-3 |
| Status | active |
| Sunset date | 2030-06-25 |
| Overall level | 1 |
| Module type | Software-hybrid |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Intel Corporation · website |
| Software versions | 1.3.1 |
| Hardware versions | 4940 (rev 40) |
Module description
Quoted from the NIST CMVP entry for this certificate.
Intel® QuickAssist Technology (QAT) Provider which supports the ability to accelerate the operations from the stand OpenSSL 3.0.8 to basic Intel instruction set, to either hardware acceleration path or via the optimized software acceleration path.
Security level exceptions
- Non-invasive security: N/A
- Mitigation of other attacks: N/A
Approved algorithms (19)
| Algorithm | CAVP certificates |
|---|---|
| AES-GCM | A4390, A4391 |
| DSA SigGen (FIPS186-4) | A4390 |
| DSA SigVer (FIPS186-4) | A4390 |
| ECDSA SigGen (FIPS186-4) | A4389, A4390 |
| ECDSA SigVer (FIPS186-4) | A4389, A4390 |
| KAS-ECC-SSC Sp800-56Ar3 | A4389, A4390 |
| KAS-FFC-SSC Sp800-56Ar3 | A4390 |
| RSA SigGen (FIPS186-4) | A4389, A4390 |
| RSA SigVer (FIPS186-4) | A4389, A4390, A4392 |
| SHA2-224 | A4391 |
| SHA2-256 | A4391, A4392 |
| SHA2-384 | A4391 |
| SHA2-512 | A4391 |
| SHA3-224 | A4390 |
| SHA3-256 | A4390 |
| SHA3-384 | A4390 |
| SHA3-512 | A4390 |
| TLS v1.2 KDF RFC7627 | A4390 |
| TLS v1.3 KDF | A4390 |
Tested configurations
- Red Hat Enterprise Linux 9.0 on StreamEagle Server with Intel Xeon Platinum 8488C with PAA
Validation history
| Date | Type | Lab |
|---|---|---|
| 2025-06-26 | Initial | DEKRA Testing and Certification S.A.U |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2025-06-26
Known CVEs in this module family (heuristic match)
Name-based association with the module's product family, not a statement about the validated boundary. See methodology.
| CVE | CVSS | Severity |
|---|---|---|
| CVE-2025-33000 | 8.8 | HIGH |
| CVE-2022-21804 | 8.4 | HIGH |
| CVE-2022-41699 | 8.2 | HIGH |
| CVE-2023-28741 | 7.9 | HIGH |
| CVE-2020-12333 | 7.8 | HIGH |
| CVE-2024-31858 | 7.8 | HIGH |
| CVE-2025-27713 | 7.8 | HIGH |
| CVE-2026-20714 | 7.8 | HIGH |
| CVE-2026-20767 | 7.8 | HIGH |
| CVE-2022-36397 | 7.3 | HIGH |
| CVE-2022-37340 | 6.7 | MEDIUM |
| CVE-2022-40972 | 6.7 | MEDIUM |
| CVE-2023-28740 | 6.7 | MEDIUM |
| CVE-2024-29223 | 6.7 | MEDIUM |
| CVE-2025-32732 | 6.6 | MEDIUM |
| CVE-2026-20717 | 6.6 | MEDIUM |
| CVE-2026-20782 | 6.6 | MEDIUM |
| CVE-2026-20905 | 6.6 | MEDIUM |
| CVE-2022-41771 | 6.5 | MEDIUM |
| CVE-2025-24519 | 6.5 | MEDIUM |
| CVE-2025-27710 | 6.5 | MEDIUM |
| CVE-2025-32446 | 6.5 | MEDIUM |
| CVE-2026-20771 | 6.1 | MEDIUM |
| CVE-2022-21239 | 5.6 | MEDIUM |
| CVE-2025-31937 | 5.6 | MEDIUM |
| CVE-2018-12193 | 5.5 | MEDIUM |
| CVE-2025-20090 | 5.5 | MEDIUM |
| CVE-2025-26694 | 5.5 | MEDIUM |
| CVE-2026-20881 | 5.5 | MEDIUM |
| CVE-2026-20914 | 5.5 | MEDIUM |
| CVE-2024-31153 | 5 | MEDIUM |
| CVE-2025-30509 | 3.8 | LOW |
| CVE-2022-41621 | 3.3 | LOW |
| CVE-2022-41808 | 3.3 | LOW |
| CVE-2025-32088 | 3.3 | LOW |
| CVE-2026-20793 | 3.3 | LOW |