LiveActive security incident?Get immediate response
CVE Record

CVE-2024-56715: ionic: Fix netdev notifier unregister on failure

In the Linux kernel, the following vulnerability has been resolved: ionic: Fix netdev notifier unregister on failure If register_netdev() fails, then the driver leaks the netdev notifier. Fix this by calling ionic_lif_unregister() on register_netdev() failure. This will also call ionic_lif_unregister_phc() if it has already been registered.

HighCVSS 7.8Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

A failure while registering an Ionic network device can leave a Linux kernel network-device notifier registered. The published fix adds the missing cleanup. Although rated high at CVSS 7.8, exploitation requires local, low-privileged access, and the supplied evidence does not establish practical exploitation or observed attacks.

Executive priority

Treat as a high-priority kernel maintenance item on hosts using the Ionic driver, especially multi-user systems where local untrusted access exists. Use normal expedited patching rather than emergency internet-edge response because the documented vector is local and no active exploitation is evidenced.

Technical view

CVE-2024-56715 is a CWE-401 cleanup flaw in the Linux Ionic network driver. If register_netdev() fails, the driver does not unregister its netdev notifier. The fix invokes ionic_lif_unregister(), which also unregisters the PTP hardware clock when previously registered. The supplied CVSS vector is local, low complexity, low privileges, no user interaction, with high confidentiality, integrity, and availability impacts.

Likely exposure

Exposure is limited to systems running an affected Linux kernel with the Ionic driver relevant to the device path and where network-device registration can fail. The bundle lists several affected versions, but its version-range semantics are incomplete; validate the exact distribution kernel and backported fixes with the vendor.

Exploitation context

The CVSS vector describes a local, low-privileged attack path. CISA KEV status is false, and no supplied source reports active exploitation, a public exploit, or demonstrated weaponization. The evidence establishes the faulty cleanup path but does not explain how the scored confidentiality, integrity, and availability impacts are achieved.

Researcher notes

The strongest evidence is the upstream fix description: a notifier remains registered after register_netdev() failure. The bundle contains multiple stable commits, likely reflecting branch-specific backports, but does not map each commit to a release. The affected-version data is ambiguous and includes an unexplained value of 0, so package-level vendor verification is essential.

Mitigation direction

  • Install a vendor-supported kernel containing the applicable linked stable fix.
  • Check distribution advisories for backported fixes before relying on kernel version numbers.
  • Prioritize systems using the Ionic network driver or associated hardware.
  • Follow vendor guidance if an updated kernel is not immediately available.

Validation and detection

  • Inventory kernel versions and determine whether the Ionic driver is present or used.
  • Confirm the installed kernel package incorporates the applicable stable fix commit.
  • Review vendor security notices for precise affected and corrected package versions.
  • After updating, verify the intended kernel is running and network devices initialize normally.
Prepared
Confidence
medium
Sources
8

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-401: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2024-56715 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
7.8 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

2CVSS vectors
3Timeline events
2ADP providers
7Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

CVSS vector scores

2 official scores

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
7.8CVSS 3.1HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H1.85.9Linux
5.5CVSS 3.1MediumCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H1.83.6CISA-ADP

Vulnerability scoring details

Base CVSS 3.1 score

7.8High
CVSS 3.1 vector shape for CVE-2024-56715Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
cvssV3_1other:ssvc
CVECVE Program Container
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux30b87ab4c0b30e0f681cb7dfaab6c642dd17e454, 30b87ab4c0b30e0f681cb7dfaab6c642dd17e454, 30b87ab4c0b30e0f681cb7dfaab6c642dd17e454, 30b87ab4c0b30e0f681cb7dfaab6c642dd17e454, 30b87ab4c0b30e0f681cb7dfaab6c642dd17e454unaffected
LinuxLinux5.10, 0, 5.15.176, 6.1.122, 6.6.68, 6.12.7, 6.13affected
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.