Impact
The vulnerability is a flaw in the AMD Performance Monitoring Controller driver within the Linux kernel (CWE-459). When the driver’s STB S2D telemetry initialization fails – for example, because the S2D telemetry region cannot be ioremapped or the SMU rejects the setup – the probe routine returns early but leaves a stale LPS0 s2idle handler registered and a debugfs directory unremoved. The leftover registration corrupts the global LPS0 list, causing the kernel to hit a BUG during a subsequent reload or normal s2idle transition, which results in a kernel crash.
Affected Systems
All Linux kernel builds that contain the built‑in amd_pmc driver are potentially affected, regardless of distribution. The CNA data lists only Linux, meaning the fix is at risk. Any system that loads the amd_pmc module and encounters the kernel is at risk.
Risk and Exploitability
The CVSS score of 7.8 reflects a high local denial‑of‑service impact. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a local actor with the ability to load or reload the AMD PMC module before the initialization succeeds; they could trigger the failing path to corrupt internal structures and crash the system. It is inferred that exploitation requires kernel to reach the fault path.
OpenCVE Enrichment