CVE-2024-56691
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2024-56691 affects the Linux kernel's Intel SoC PMIC BXTWC driver implementation. The vulnerability was discovered when platformgetirq() started generating WARN() messages on IRQ 0, which should be a Linux IRQ number (vIRQ). The issue stems from flaws in the implementation of converting the driver to use the hierarchy of IRQ chips (Kernel Git).

Technical details

The vulnerability exists in the Intel SoC PMIC BXTWC driver's IRQ domain handling for USB Type-C devices. The implementation incorrectly handled the IRQ domain hierarchy when creating MFD devices, as the domain is not the same for all of them. This affects the driver's ability to properly manage interrupt requests for USB Type-C devices (Kernel Git).

Impact

The vulnerability affects the proper functioning of USB Type-C devices on systems using the Intel SoC PMIC BXTWC driver. When exploited, it could lead to improper interrupt handling for USB Type-C devices (NVD).

Mitigation and workarounds

The issue has been fixed in the Linux kernel through a patch that reworks the driver to properly respect IRQ domain when creating each MFD device separately. The fix has been implemented in various kernel versions including 6.11.0-18.18 for Ubuntu 24.10 (Ubuntu Security).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40205HIGH7.8
  • Linux KernelLinux Kernel
  • linux-hwe-6.14
NoYesNov 12, 2025
CVE-2025-40211HIGH7.1
  • Linux KernelLinux Kernel
  • linux-azure-fde-6.14
NoYesNov 21, 2025
CVE-2025-40206MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel
NoYesNov 12, 2025
CVE-2025-40210MEDIUM5.1
  • Linux KernelLinux Kernel
  • kernel-tools-libs-devel
NoYesNov 21, 2025
CVE-2025-40212N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k
NoYesNov 24, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management