In the Linux kernel, the following vulnerability has been resolved:
vfio: Fix NULL pointer dereference caused by uninitialized group->iommufd
group->iommufd is not initialized for the iommufdctxput()
[20018.331541] BUG: kernel NULL pointer dereference, address: 0000000000000000 [20018.377508] RIP: 0010:iommufdctxput+0x5/0x10 [iommufd] ... [20018.476483] Call Trace: [20018.479214] <TASK> [20018.481555] vfiogroupfopsunlioctl+0x506/0x690 [vfio] [20018.487586] _x64sysioctl+0x6a/0xb0 [20018.491773] ? tracehardirqson+0xc5/0xe0 [20018.496347] dosyscall64+0x67/0x90 [20018.500340] entrySYSCALL64after_hwframe+0x4b/0xb5
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/54xxx/CVE-2023-54174.json"
}