-
CVE-2026-90136
- EPSS 0.2%
- Veröffentlicht 17.09.2026 16:06:35
- Zuletzt bearbeitet 17.09.2026 17:17:06
- Erkennungen
platform/x86/amd/hsmp: Reject negative power cap writes in hwmon
In the Linux kernel, the following vulnerability has been resolved:
platform/x86/amd/hsmp: Reject negative power cap writes in hwmon
hsmp_hwmon_write() takes the user-supplied hwmon value as a signed long
and assigns "val / MICROWATT_PER_MILLIWATT" to msg.args[0], which is a
__u32. MICROWATT_PER_MILLIWATT is an unsigned long, so a negative write
to power1_cap (e.g. "echo -1 > power1_cap") is first converted to a huge
unsigned value by the division and then stored into the u32 argument.
As a result a nonsensical, multi-gigawatt socket power limit is sent to
the SMU via HSMP_SET_SOCKET_POWER_LIMIT instead of the write being
rejected.
Reject negative values with -EINVAL before the conversion.
Tested with HSMP enabled:
CAP=$(dirname $(grep -l amd_hsmp_hwmon \
/sys/class/hwmon/hwmon*/name | head -1))/power1_cap
# negative write
echo -1000000 > $CAP ; echo "ret=$?"
# valid positive write must still work
echo 400000000 > $CAP ; echo "ret=$?"
Before:
# echo -1000000 > $CAP ; echo "ret=$?"
ret=0 <- accepted; bogus limit sent to SMU
# echo 400000000 > $CAP ; echo "ret=$?"
ret=0
After:
# echo -1000000 > $CAP ; echo "ret=$?"
bash: echo: write error: Invalid argument
ret=1 <- rejected with -EINVAL
# echo 400000000 > $CAP ; echo "ret=$?"
ret=0 <- valid write still worksDaten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
92c025db52bb94a032eb3d473bb81e62c19ddbd3
Version <
2c09cadec116eba3fdbcb5d8d8641f6777d4a11f
Status
affected
Version
92c025db52bb94a032eb3d473bb81e62c19ddbd3
Version <
1b0a3d915320f1600e5ff43f8bc21b73118480b8
Status
affected
Version
92c025db52bb94a032eb3d473bb81e62c19ddbd3
Version <
3921bb8635ff2836622df1cdf3194d4f3c1835a4
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.16
Status
affected
Version
0
Version <
6.16
Status
unaffected
Version <=
6.18.*
Version
6.18.52
Status
unaffected
Version <=
7.2.*
Version
7.2.6
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.099 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/2c09cadec116eba3fdbcb5d8d8641f6777d4a11f
https://git.kernel.org/stable/c/1b0a3d915320f1600e5ff43f8bc21b73118480b8
https://git.kernel.org/stable/c/3921bb8635ff2836622df1cdf3194d4f3c1835a4