CVE-2024-56683
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2024-56683 affects the Linux kernel's DRM (Direct Rendering Manager) subsystem, specifically the VC4 HDMI driver. The vulnerability was discovered and disclosed on December 28, 2024. The issue occurs when attempting to read HDMI debug registers through the debugfs interface (/sys/kernel/debug/dri/1/hdmi1_regs) while the HDMI is disconnected and the system is in a suspended state (NVD).

Technical details

The vulnerability is caused by the power management (PM) suspend code disabling the DVP clock, which is a gate of the 108MHz clock in DVP_HT_RPI_MISC_CONFIG. When attempting to access the debug registers in this state, it results in a hanging AXI bus. The fix involves protecting against this condition by properly managing the power state through pm_runtime_resume_and_get() and pm_runtime_put() calls around the debug register access (Kernel Commit).

Impact

When exploited, this vulnerability can cause a fatal system hang when attempting to read HDMI debug registers while the HDMI is disconnected. This can lead to a denial of service condition requiring a system restart (NVD).

Mitigation and workarounds

The issue has been fixed in various Linux kernel versions. The fix has been backported to multiple stable kernel branches. Debian has addressed this in version 6.1.6.1.128-1~deb11u1, Ubuntu has fixed it in version 6.11.0-18.18 for 24.10 (oracular), and other distributions have also released patches (Debian LTS, Ubuntu).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-68753HIGH7.8
  • Linux KernelLinux Kernel
  • linux-oem-6.14
NoYesJan 05, 2026
CVE-2025-68756HIGH7.1
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug
NoYesJan 05, 2026
CVE-2025-68764MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-rt-64k-core
NoYesJan 05, 2026
CVE-2025-68758MEDIUM5.5
  • Linux KernelLinux Kernel
  • linux-nvidia-tegra-5.15
NoYesJan 05, 2026
CVE-2025-68762N/AN/A
  • Linux KernelLinux Kernel
  • linux-aws-fips
NoYesJan 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management