Description
In the Linux kernel, the following vulnerability has been resolved:

platform/x86/amd/hsmp: Reject negative power cap writes in hwmon

hsmp_hwmon_write() takes the user-supplied hwmon value as a signed long
and assigns "val / MICROWATT_PER_MILLIWATT" to msg.args[0], which is a
__u32. MICROWATT_PER_MILLIWATT is an unsigned long, so a negative write
to power1_cap (e.g. "echo -1 > power1_cap") is first converted to a huge
unsigned value by the division and then stored into the u32 argument.

As a result a nonsensical, multi-gigawatt socket power limit is sent to
the SMU via HSMP_SET_SOCKET_POWER_LIMIT instead of the write being
rejected.

Reject negative values with -EINVAL before the conversion.

Tested with HSMP enabled:

CAP=$(dirname $(grep -l amd_hsmp_hwmon \
/sys/class/hwmon/hwmon*/name | head -1))/power1_cap

# negative write
echo -1000000 > $CAP ; echo "ret=$?"
# valid positive write must still work
echo 400000000 > $CAP ; echo "ret=$?"

Before:
# echo -1000000 > $CAP ; echo "ret=$?"
ret=0 <- accepted; bogus limit sent to SMU
# echo 400000000 > $CAP ; echo "ret=$?"
ret=0

After:
# echo -1000000 > $CAP ; echo "ret=$?"
bash: echo: write error: Invalid argument
ret=1 <- rejected with -EINVAL
# echo 400000000 > $CAP ; echo "ret=$?"
ret=0 <- valid write still works
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Hardware power limit overflow could lead to instability or failure
Action: Apply Patch
AI Analysis

Impact

The flaw occurs in the amd_hsmp_hwmon interface of the Linux kernel where a caller writes a power cap value. The code treats the supplied value as a signed long, divides by MICROWATT_PER_MILLIWATT, and stores the result in a __u32 field. When a negative value such as –1 is written, the signed value is first converted to a large unsigned number during the division, producing a multi‑gigawatt limit that is then sent to the SMU via HSMP_SET_SOCKET_POWER_LIMIT. The kernel previously accepted this write without rejection, allowing the SMU to receive an out‑of‑range power limit that could induce undefined behaviour, including power cycling or a system crash. This is a signed to unsigned conversion flaw (CWE‑195).

Affected Systems

The vulnerability affects any Linux kernel configuration that enables the AMD HSMP hardware monitoring driver (amd_hsmp_hwmon). It is present in all kernel versions prior to the commit that introduced the fix; the exact version range is not specified, but it applies to kernel trees that ship the hsmp_hwmon interface.

Risk and Exploitability

The EPSS score is below 1 %, and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of public exploitation. The exploit requires at least local write access to the sysfs file /sys/class/hwmon/hwmon*/power1_cap, which is normally restricted to privileged users. Once accessed, the attacker can cause the SMU to receive an implausible power limit, potentially leading to hardware instability or a system reboot. The severity could be considered medium to high if the hardware behaves unpredictably, but no CVSS score is provided in the public data.

Generated by OpenCVE AI on September 18, 2026 at 22:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the commit fixing the signed to unsigned conversion in hsmp_hwmon_write
  • If an official kernel update is not yet available, manually apply the upstream patch to the kernel source and recompile the kernel
  • As an interim workaround, disable write access to the power1_cap attribute by changing its permissions to read‑only or disabling the amd_hsmp_hwmon driver altogether

Generated by OpenCVE AI on September 18, 2026 at 22:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-195

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd/hsmp: Reject negative power cap writes in hwmon hsmp_hwmon_write() takes the user-supplied hwmon value as a signed long and assigns "val / MICROWATT_PER_MILLIWATT" to msg.args[0], which is a __u32. MICROWATT_PER_MILLIWATT is an unsigned long, so a negative write to power1_cap (e.g. "echo -1 > power1_cap") is first converted to a huge unsigned value by the division and then stored into the u32 argument. As a result a nonsensical, multi-gigawatt socket power limit is sent to the SMU via HSMP_SET_SOCKET_POWER_LIMIT instead of the write being rejected. Reject negative values with -EINVAL before the conversion. Tested with HSMP enabled: CAP=$(dirname $(grep -l amd_hsmp_hwmon \ /sys/class/hwmon/hwmon*/name | head -1))/power1_cap # negative write echo -1000000 > $CAP ; echo "ret=$?" # valid positive write must still work echo 400000000 > $CAP ; echo "ret=$?" Before: # echo -1000000 > $CAP ; echo "ret=$?" ret=0 <- accepted; bogus limit sent to SMU # echo 400000000 > $CAP ; echo "ret=$?" ret=0 After: # echo -1000000 > $CAP ; echo "ret=$?" bash: echo: write error: Invalid argument ret=1 <- rejected with -EINVAL # echo 400000000 > $CAP ; echo "ret=$?" ret=0 <- valid write still works
Title platform/x86/amd/hsmp: Reject negative power cap writes in hwmon
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:35.190Z

Reserved: 2026-09-11T19:38:34.788Z

Link: CVE-2026-90136

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:06.173

Modified: 2026-09-17T17:17:06.173

Link: CVE-2026-90136

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T22:30:15Z

Weaknesses
  • CWE-195

    Signed to Unsigned Conversion Error