cbcvebase.
CVE-2024-56691
published 2024-12-28

CVE-2024-56691: In the Linux kernel, the following vulnerability has been resolved: mfd: intel_soc_pmic_bxtwc: Use IRQ domain for USB Type-C device While design wise the idea…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
12.3th percentile
In the Linux kernel, the following vulnerability has been resolved: mfd: intel_soc_pmic_bxtwc: Use IRQ domain for USB Type-C device While design wise the idea of converting the driver to use the hierarchy of the IRQ chips is correct, the implementation has (inherited) flaws. This was unveiled when platform_get_irq() had started WARN() on IRQ 0 that is supposed to be a Linux IRQ number (also known as vIRQ). Rework the driver to respect IRQ domain when creating each MFD device separately, as the domain is not the same for all of them.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux>= 9c6235c8633210cc2da0882e2e9d6ff90aa37503 < 0997e77c51330c2866a4f39480e762cca92ad9530997e77c51330c2866a4f39480e762cca92ad953
linuxlinux>= 9c6235c8633210cc2da0882e2e9d6ff90aa37503 < 0b648968bfa4f5c9c4983bca9f2de17626ed6fb60b648968bfa4f5c9c4983bca9f2de17626ed6fb6
linuxlinux>= 9c6235c8633210cc2da0882e2e9d6ff90aa37503 < 23230ac3c5ca3f154b64849d1cf50583b4e6b98c23230ac3c5ca3f154b64849d1cf50583b4e6b98c
linuxlinux>= 9c6235c8633210cc2da0882e2e9d6ff90aa37503 < c310e6916c0b297011d0fec03f168a6b24e9e984c310e6916c0b297011d0fec03f168a6b24e9e984
linuxlinux>= 9c6235c8633210cc2da0882e2e9d6ff90aa37503 < e1ef62e8d262e3f27446d26742208c1c81e9ee18e1ef62e8d262e3f27446d26742208c1c81e9ee18
linuxlinux>= 9c6235c8633210cc2da0882e2e9d6ff90aa37503 < 518e414d24e7037d6cc7198e942bf47fe6f5e8e1518e414d24e7037d6cc7198e942bf47fe6f5e8e1
linuxlinux>= 9c6235c8633210cc2da0882e2e9d6ff90aa37503 < 87a07a5b0b296e489c606ca95ffc16c18821975b87a07a5b0b296e489c606ca95ffc16c18821975b
linuxlinux>= 9c6235c8633210cc2da0882e2e9d6ff90aa37503 < 686fb77712a4bc94b76a0c5ae74c60118b7a0d79686fb77712a4bc94b76a0c5ae74c60118b7a0d79
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.3-16.12.3-1
linuxlinux_kernel>= 0 < 6.12.3-16.12.3-1
linuxlinux_kernel>= 0 < 5.4.0-211.2315.4.0-211.231
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 4.9 < 5.4.2875.4.287
linuxlinux_kernel>= 5.11 < 5.15.1745.15.174
linuxlinux_kernel>= 5.16 < 6.1.1206.1.120
linuxlinux_kernel>= 5.5 < 5.10.2315.10.231
linuxlinux_kernel>= 6.12 < 6.12.26.12.2
linuxlinux_kernel>= 6.2 < 6.6.646.6.64

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.