{"id":"DEBIAN-CVE-2024-56668","details":"In the Linux kernel, the following vulnerability has been resolved:  iommu/vt-d: Fix qi_batch NULL pointer with nested parent domain  The qi_batch is allocated when assigning cache tag for a domain. While for nested parent domain, it is missed. Hence, when trying to map pages to the nested parent, NULL dereference occurred. Also, there is potential memleak since there is no lock around domain-\u003eqi_batch allocation.  To solve it, add a helper for qi_batch allocation, and call it in both the __cache_tag_assign_domain() and __cache_tag_assign_parent_domain().    BUG: kernel NULL pointer dereference, address: 0000000000000200   #PF: supervisor read access in kernel mode   #PF: error_code(0x0000) - not-present page   PGD 8104795067 P4D 0   Oops: Oops: 0000 [#1] PREEMPT SMP NOPTI   CPU: 223 UID: 0 PID: 4357 Comm: qemu-system-x86 Not tainted 6.13.0-rc1-00028-g4b50c3c3b998-dirty #2632   Call Trace:    ? __die+0x24/0x70    ? page_fault_oops+0x80/0x150    ? do_user_addr_fault+0x63/0x7b0    ? exc_page_fault+0x7c/0x220    ? asm_exc_page_fault+0x26/0x30    ? cache_tag_flush_range_np+0x13c/0x260    intel_iommu_iotlb_sync_map+0x1a/0x30    iommu_map+0x61/0xf0    batch_to_domain+0x188/0x250    iopt_area_fill_domains+0x125/0x320    ? rcu_is_watching+0x11/0x50    iopt_map_pages+0x63/0x100    iopt_map_common.isra.0+0xa7/0x190    iopt_map_user_pages+0x6a/0x80    iommufd_ioas_map+0xcd/0x1d0    iommufd_fops_ioctl+0x118/0x1c0    __x64_sys_ioctl+0x93/0xc0    do_syscall_64+0x71/0x140    entry_SYSCALL_64_after_hwframe+0x76/0x7e","modified":"2026-09-15T09:03:04.737305052Z","published":"2024-12-27T15:15:26.693Z","upstream":["CVE-2024-56668"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-56668"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.6-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-56668.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.6-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-56668.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}