7.7

CVE-2026-81016

platform/x86/amd/pmc: Propagate SMU errors and validate S2D address

In the Linux kernel, the following vulnerability has been resolved:

platform/x86/amd/pmc: Propagate SMU errors and validate S2D address

amd_stb_s2d_init() discards the return value of several S2D SMU commands.
When the SMU refuses a command (e.g. "SMU cmd failed. err: 0xff") the
failure is only noticed indirectly - if at all - and reported as -EIO,
masking the real error.

More seriously, the S2D_PHYS_ADDR_LOW/HIGH return values are ignored, so
on failure phys_addr_low/hi are left uninitialised and the assembled
address is passed straight to devm_ioremap().  When the SMU leaves them at
zero this maps physical address 0 and trips the ioremap-on-RAM warning:

  amd_pmc AMDI000B:00: SMU cmd failed. err: 0xff
  ioremap on RAM at 0x0000000000000000 - 0x0000000000ffffff
  WARNING: CPU: 13 PID: 4592 at arch/x86/mm/ioremap.c:...

Check the return value of each SMU command and propagate it, and reject a
zero physical address before calling devm_ioremap().
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 3d7d407dfb05b257e15cb0c6b056428a4a8c2e5d
Version < 638e1ca5d4e2b4fdbb209db64926d013b34f3b79
Status affected
Version 3d7d407dfb05b257e15cb0c6b056428a4a8c2e5d
Version < 8178f59d76570b152d836bde07f5997f15861f04
Status affected
Version 3d7d407dfb05b257e15cb0c6b056428a4a8c2e5d
Version < 775d4cde1f9737796ce7d8393521e9e8c5b49891
Status affected
Version 3d7d407dfb05b257e15cb0c6b056428a4a8c2e5d
Version < 0225c1d637687b03726f00ac65b6def843d2c464
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.18
Status affected
Version 0
Version < 5.18
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.078
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.7 2.5 5.2
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/8178f59d76570b152d836bde07f5997f15861f04
https://git.kernel.org/stable/c/775d4cde1f9737796ce7d8393521e9e8c5b49891
https://git.kernel.org/stable/c/0225c1d637687b03726f00ac65b6def843d2c464
https://git.kernel.org/stable/c/638e1ca5d4e2b4fdbb209db64926d013b34f3b79