CVE-2023-54174Access of Uninitialized Pointer in Linux

Severity
5.5MEDIUM
No vector
EPSS
0.0%
top 92.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 30

Description

In the Linux kernel, the following vulnerability has been resolved: vfio: Fix NULL pointer dereference caused by uninitialized group->iommufd group->iommufd is not initialized for the iommufd_ctx_put() [20018.331541] BUG: kernel NULL pointer dereference, address: 0000000000000000 [20018.377508] RIP: 0010:iommufd_ctx_put+0x5/0x10 [iommufd] ... [20018.476483] Call Trace: [20018.479214] [20018.481555] vfio_group_fops_unl_ioctl+0x506/0x690 [vfio] [20018.487586] __x64_sys_ioctl+0x6a/0xb0 [20018.49

Affected Packages3 packages

Linuxlinux/linux_kernel6.2.06.2.3
CVEListV5linux/linux9eefba8002c27d65ab52a533fd0611b099b735918f24eef598ce7cce0bbefe0ec642bcc031d0f528+2
debiandebian/linux

🔴Vulnerability Details

3
OSV
vfio: Fix NULL pointer dereference caused by uninitialized group->iommufd2025-12-30
OSV
CVE-2023-54174: In the Linux kernel, the following vulnerability has been resolved: vfio: Fix NULL pointer dereference caused by uninitialized group->iommufd group->i2025-12-30
GHSA
GHSA-p5cq-xjmm-63wj: In the Linux kernel, the following vulnerability has been resolved: vfio: Fix NULL pointer dereference caused by uninitialized group->iommufd group-2025-12-30

📋Vendor Advisories

2
Red Hat
kernel: vfio: Fix NULL pointer dereference caused by uninitialized group->iommufd2025-12-30
Debian
CVE-2023-54174: linux - In the Linux kernel, the following vulnerability has been resolved: vfio: Fix N...2023

🕵️Threat Intelligence

1
Wiz
CVE-2023-54174 Impact, Exploitability, and Mitigation Steps | Wiz