Description
In the Linux kernel, the following vulnerability has been resolved:

platform/x86/amd/pmc: Propagate SMU errors and validate S2D address

amd_stb_s2d_init() discards the return value of several S2D SMU commands.
When the SMU refuses a command (e.g. "SMU cmd failed. err: 0xff") the
failure is only noticed indirectly - if at all - and reported as -EIO,
masking the real error.

More seriously, the S2D_PHYS_ADDR_LOW/HIGH return values are ignored, so
on failure phys_addr_low/hi are left uninitialised and the assembled
address is passed straight to devm_ioremap(). When the SMU leaves them at
zero this maps physical address 0 and trips the ioremap-on-RAM warning:

amd_pmc AMDI000B:00: SMU cmd failed. err: 0xff
ioremap on RAM at 0x0000000000000000 - 0x0000000000ffffff
WARNING: CPU: 13 PID: 4592 at arch/x86/mm/ioremap.c:...

Check the return value of each SMU command and propagate it, and reject a
zero physical address before calling devm_ioremap().
Published: 2026-09-11
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Potential kernel instability from mapping physical address 0
Action: Apply patch
AI Analysis

Impact

This flaw, classified as CWE-908, involves improper handling of SMU command return values and uninitialized address usage, leading to potential kernel instability. The flaw resides in the Linux kernel’s AMD Performance Monitoring Counters (PMC) driver for x86 CPUs. During initialization, the function amd_stb_s2d_init() discards the return values of several System Management Unit (SMU) commands, masking real failures as a generic I/O error. Even more critically, the low and high physical address values produced by the SMU are ignored when a command fails, leaving the address uninitialized. If the SMU returns zeros, the driver passes this uninitialized address to devm_ioremap(), which attempts to map physical address 0. This produces an ioremap‑on‑RAM warning and can lead to undefined kernel behavior or instability.

Affected Systems

The issue affects the Linux kernel’s AMD PMC driver on x86 platforms. The CPE string indicates a general Linux kernel; no specific kernel versions are listed in the data, so the affected release range is unknown.

Risk and Exploitability

The CVSS base score of 7.7 indicates high severity, while the EPSS score of <1% shows a low estimated probability of exploitation. The flaw requires kernel‑mode execution; based on the description, it is inferred that an attacker would need local privileged access or the ability to load a malicious kernel module to trigger the vulnerable path. The likely attack vector is an attacker with local privileged access exploiting the AMD PMC driver, either by injecting a crafted kernel module or compromising kernel space. Because the SMU error is masked as a generic I/O failure, exploitation may be difficult and it is not currently catalogued in CISA’s KEV list.

Generated by OpenCVE AI on September 21, 2026 at 03:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to a Linux kernel version that includes the AMD PMC fix from the referenced commit.
  • If a kernel update is not immediately available, compile the kernel without AMD PMU support or load a shim that disables the AMD PMU driver.
  • Configure log monitoring to alert on ioremap‑on‑RAM warnings or SMU failure messages to detect any triggering activity.

Generated by OpenCVE AI on September 21, 2026 at 03:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 11:15:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-908
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd/pmc: Propagate SMU errors and validate S2D address amd_stb_s2d_init() discards the return value of several S2D SMU commands. When the SMU refuses a command (e.g. "SMU cmd failed. err: 0xff") the failure is only noticed indirectly - if at all - and reported as -EIO, masking the real error. More seriously, the S2D_PHYS_ADDR_LOW/HIGH return values are ignored, so on failure phys_addr_low/hi are left uninitialised and the assembled address is passed straight to devm_ioremap(). When the SMU leaves them at zero this maps physical address 0 and trips the ioremap-on-RAM warning: amd_pmc AMDI000B:00: SMU cmd failed. err: 0xff ioremap on RAM at 0x0000000000000000 - 0x0000000000ffffff WARNING: CPU: 13 PID: 4592 at arch/x86/mm/ioremap.c:... Check the return value of each SMU command and propagate it, and reject a zero physical address before calling devm_ioremap().
Title platform/x86/amd/pmc: Propagate SMU errors and validate S2D address
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-03T10:56:24.645Z

Reserved: 2026-08-26T14:34:25.813Z

Link: CVE-2026-81016

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:10.560

Modified: 2026-10-03T11:17:41.710

Link: CVE-2026-81016

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:43:04Z

Links: CVE-2026-81016 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T03:15:09Z

Weaknesses
  • CWE-908

    Use of Uninitialized Resource