CVE-2024-56680
Last modified
CVE-2024-56680 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: media: intel/ipu6: do not handle interrupts when device is disabled Some IPU6 devices have shared interrupts. We need to handle properly case when interrupt is triggered from other device on shared irq line and IPU6 itself disabled. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: media: intel/ipu6: do not handle interrupts when device is disabled Some IPU6 devices have shared interrupts. We need to handle properly case when interrupt is triggered from other device on shared irq line and IPU6 itself disabled. In such case we get 0xffffffff from ISR_STATUS register and handle all irq's cases, for what we are not not prepared and usually hang the whole system. To avoid the issue use pm_runtime_get_if_active() to check if the device is enabled and prevent suspending it when we handle irq until the end of irq. Additionally use synchronize_irq() in suspend
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 6.10, < 6.11.11 |
| Linux | Linux Kernel | >= 6.12, < 6.12.2 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-56680?
How severe is CVE-2024-56680?
How do I fix CVE-2024-56680?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-56675In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2024-56676In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-56677In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-56678In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2024-56679In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-5668The Lightbox & Modal Popup WordPress Plugin – FooBox plugin …5.4
- CVE-2024-56681In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-56682In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-56683In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-56684In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2024-56685In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-56686Rejected reason: This CVE ID has been rejected or withdrawn …
Are you affected by CVE-2024-56680?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
