Impact
The flaw occurs in the amd_hsmp_hwmon interface of the Linux kernel where a caller writes a power cap value. The code treats the supplied value as a signed long, divides by MICROWATT_PER_MILLIWATT, and stores the result in a __u32 field. When a negative value such as –1 is written, the signed value is first converted to a large unsigned number during the division, producing a multi‑gigawatt limit that is then sent to the SMU via HSMP_SET_SOCKET_POWER_LIMIT. The kernel previously accepted this write without rejection, allowing the SMU to receive an out‑of‑range power limit that could induce undefined behaviour, including power cycling or a system crash. This is a signed to unsigned conversion flaw (CWE‑195).
Affected Systems
The vulnerability affects any Linux kernel configuration that enables the AMD HSMP hardware monitoring driver (amd_hsmp_hwmon). It is present in all kernel versions prior to the commit that introduced the fix; the exact version range is not specified, but it applies to kernel trees that ship the hsmp_hwmon interface.
Risk and Exploitability
The EPSS score is below 1 %, and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of public exploitation. The exploit requires at least local write access to the sysfs file /sys/class/hwmon/hwmon*/power1_cap, which is normally restricted to privileged users. Once accessed, the attacker can cause the SMU to receive an implausible power limit, potentially leading to hardware instability or a system reboot. The severity could be considered medium to high if the hardware behaves unpredictably, but no CVSS score is provided in the public data.
OpenCVE Enrichment