* CVE-2026-81016: platform/x86/amd/pmc: Propagate SMU errors and validate S2D address
@ 2026-09-11 19:42 Greg Kroah-Hartman
0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-09-11 19:42 UTC (permalink / raw)
To: linux-cve-announce; +Cc: Greg Kroah-Hartman
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
platform/x86/amd/pmc: Propagate SMU errors and validate S2D address
amd_stb_s2d_init() discards the return value of several S2D SMU commands.
When the SMU refuses a command (e.g. "SMU cmd failed. err: 0xff") the
failure is only noticed indirectly - if at all - and reported as -EIO,
masking the real error.
More seriously, the S2D_PHYS_ADDR_LOW/HIGH return values are ignored, so
on failure phys_addr_low/hi are left uninitialised and the assembled
address is passed straight to devm_ioremap(). When the SMU leaves them at
zero this maps physical address 0 and trips the ioremap-on-RAM warning:
amd_pmc AMDI000B:00: SMU cmd failed. err: 0xff
ioremap on RAM at 0x0000000000000000 - 0x0000000000ffffff
WARNING: CPU: 13 PID: 4592 at arch/x86/mm/ioremap.c:...
Check the return value of each SMU command and propagate it, and reject a
zero physical address before calling devm_ioremap().
The Linux kernel CVE team has assigned CVE-2026-81016 to this issue.
Affected and fixed versions
===========================
Issue introduced in 5.18 with commit 3d7d407dfb05b257e15cb0c6b056428a4a8c2e5d and fixed in 6.18.50 with commit 8178f59d76570b152d836bde07f5997f15861f04
Issue introduced in 5.18 with commit 3d7d407dfb05b257e15cb0c6b056428a4a8c2e5d and fixed in 7.2.4 with commit 775d4cde1f9737796ce7d8393521e9e8c5b49891
Issue introduced in 5.18 with commit 3d7d407dfb05b257e15cb0c6b056428a4a8c2e5d and fixed in 7.3-rc1 with commit 0225c1d637687b03726f00ac65b6def843d2c464
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-81016
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
drivers/platform/x86/amd/pmc/mp1_stb.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/8178f59d76570b152d836bde07f5997f15861f04
https://git.kernel.org/stable/c/775d4cde1f9737796ce7d8393521e9e8c5b49891
https://git.kernel.org/stable/c/0225c1d637687b03726f00ac65b6def843d2c464
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-09-11 19:49 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-11 19:42 CVE-2026-81016: platform/x86/amd/pmc: Propagate SMU errors and validate S2D address Greg Kroah-Hartman
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.