From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2E12929ACFD for ; Fri, 11 Sep 2026 19:49:57 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156209; cv=none; b=HiDJ67EVFGyidX29sTGQ9IKdY/hdvLEPPfqKyDPgPQQHdQEakm6+c9lshcRPjo93FOyStgPjBCmw8U6tbXaR69+CJtE0ci+G54uey77DDnq5pCTNAHGB4kOzrSlRXiQoms2ZTJL9oC6M6qRB943xsSv1dL5qN+fy8fb4zXDKteU= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156209; c=relaxed/simple; bh=aCyukSQrnWEx2HkatVDQqBz/Upre1mDCnXVuJom8UiU=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=PbSNdI+IJQyiUVEG8dKH/T9Zp+K47zwb1HcaTPuiwlM2Eh4LH8LE9FGjQroeRIXuzANmL97n9fwNr1UetxjhGSHY2ORP3qsA2IoFLJ4IfEcoo2rMeqB97QNWYd5ck9bENKSWt/UCxB8RnwsowrdPZMpCyU/ZLP0QInSd0OYmT0s= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=vy4HYag+; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="vy4HYag+" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 6AC8B1F000FF; Fri, 11 Sep 2026 19:49:49 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156190; bh=tdmNNnr/mYJsz+a25G0rWpFTmYQiabpcVr9hC7FxcOY=; h=From:To:Cc:Subject:Date:Reply-To; b=vy4HYag+nzUpC+6OA2wwSz0+JneiCq5SRdDjVtfPg3LnCMX8Hwg39+yQ9zee2nvGm DL6AEhmmUDD32GVtbeSd2A2qu1zKIjrJC2OFc1fEVcBc8CIeRJNm8YIuOLI6mbr+5q RXc+W1szDuQQ2GqE8nQ33IXh6pjJk/TX5+ZB4bhs= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-81016: platform/x86/amd/pmc: Propagate SMU errors and validate S2D address Date: Fri, 11 Sep 2026 21:42:02 +0200 Message-ID: <2026091154-CVE-2026-81016-afcb@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=2859; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=aolQcYEuQhHYHUniLZkCgcniJAqniV7394INI92sg4o=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIt38t66q5X6/sezK/k4jmQua6ifn9W7e3j9tX3LNy qVr1GoMOmJZGASZGGTFFFm+bOM5ur/ikKKXoe1pmDmsTCBDGLg4BWAiUQwMcziKJGed01jzbL/p kdnyV5WO7E77LcMwP2LOecbP222/R05+zfhSxcKvas6OBQA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd/pmc: Propagate SMU errors and validate S2D address amd_stb_s2d_init() discards the return value of several S2D SMU commands. When the SMU refuses a command (e.g. "SMU cmd failed. err: 0xff") the failure is only noticed indirectly - if at all - and reported as -EIO, masking the real error. More seriously, the S2D_PHYS_ADDR_LOW/HIGH return values are ignored, so on failure phys_addr_low/hi are left uninitialised and the assembled address is passed straight to devm_ioremap(). When the SMU leaves them at zero this maps physical address 0 and trips the ioremap-on-RAM warning: amd_pmc AMDI000B:00: SMU cmd failed. err: 0xff ioremap on RAM at 0x0000000000000000 - 0x0000000000ffffff WARNING: CPU: 13 PID: 4592 at arch/x86/mm/ioremap.c:... Check the return value of each SMU command and propagate it, and reject a zero physical address before calling devm_ioremap(). The Linux kernel CVE team has assigned CVE-2026-81016 to this issue. Affected and fixed versions =========================== Issue introduced in 5.18 with commit 3d7d407dfb05b257e15cb0c6b056428a4a8c2e5d and fixed in 6.18.50 with commit 8178f59d76570b152d836bde07f5997f15861f04 Issue introduced in 5.18 with commit 3d7d407dfb05b257e15cb0c6b056428a4a8c2e5d and fixed in 7.2.4 with commit 775d4cde1f9737796ce7d8393521e9e8c5b49891 Issue introduced in 5.18 with commit 3d7d407dfb05b257e15cb0c6b056428a4a8c2e5d and fixed in 7.3-rc1 with commit 0225c1d637687b03726f00ac65b6def843d2c464 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-81016 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/platform/x86/amd/pmc/mp1_stb.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/8178f59d76570b152d836bde07f5997f15861f04 https://git.kernel.org/stable/c/775d4cde1f9737796ce7d8393521e9e8c5b49891 https://git.kernel.org/stable/c/0225c1d637687b03726f00ac65b6def843d2c464