Description
In the Linux kernel, the following vulnerability has been resolved:

cpufreq: amd-pstate-ut: Skip tests when amd-pstate driver is not active

The crash issue may occur when modprobe amd_pstate_ut on intel platform.

amd_pstate_ut: 1 amd_pstate_ut_acpi_cpc_valid success!
amd_pstate_ut: 2 amd_pstate_ut_check_enabled success!
BUG: kernel NULL pointer dereference, address: 0000000000000080
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0
Oops: 0000 [#1] SMP NOPTI
CPU: 0 PID: 20300 Comm: modprobe
Kdump: loaded Tainted: G O 6.6.0-0010.rc1.ctl4.x86_64 #1
Hardware name: FiberHome R2200 V5/Xeon Boards, BIOS 3.1a 02/24/2020
RIP: 0010:amd_pstate_ut_check_perf+0x141/0x280 [amd_pstate_ut]
Call Trace:
<TASK>
amd_pstate_ut_init+0x1b/0xff0 [amd_pstate_ut]
? __pfx_amd_pstate_ut_init+0x10/0x10 [amd_pstate_ut]
do_one_initcall+0x42/0x2e0
? kmalloc_trace+0x26/0x90
do_init_module+0x60/0x240
__se_sys_init_module+0x185/0x1c0
do_syscall_64+0x62/0x190
entry_SYSCALL_64_after_hwframe+0x76/0x7e
</TASK>

Add state detection to amd pstate driver to prevent amd_pstate_ut driver
from testing on non-AMD platforms.

(ML: adjust title)
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service through Kernel Panic
Action: Apply Patch
AI Analysis

Impact

The flaw lies in the Linux kernel’s amd_pstate_ut module, which can be manually loaded with modprobe. When the module is loaded on hardware that is not powered by an AMD processor, the code path that checks whether the amd_pstate driver is active is bypassed, causing a NULL pointer dereference and resulting in a kernel panic. The immediate effect is a denial of service, as the system reboot or become unusable. The vulnerability does not provide a direct remote code execution pathway, but the crash can be triggered by any user with permission to load kernel modules, typically requiring elevated privileges.

Affected Systems

The issue affects any installation of the Linux kernel that includes the amd_pstate_ut module and runs on non‑AMD platforms, such as Intel x86 servers or workstations. No specific kernel version is cited, so it applies to current kernel releases that ship the module until the patch that introduces state detection is deployed.

Risk and Exploitability

The EPSS score is reported as less than 1 %, indicating a very low likelihood of widespread exploitation, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score is not provided, but the lack of exploitation and the requirement for module‑loading privileges suggest a moderate risk. Attackers would need root or module‑load capability to trigger the crash, making it a local denial‑of‑service risk rather than a remote attack vector.

Generated by OpenCVE AI on September 19, 2026 at 05:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Prevent the amd_pstate_ut module from loading on non‑AMD systems by adding a blacklist entry in */etc/modprobe.d/amd_pstate_ut.conf* with the line "blacklist amd_pstate_ut".
  • Update the kernel to a version that contains the official fix, which incorporates state detection to skip the test path on unsupported platforms.
  • If a newer kernel is unavailable, restrict module loading abilities by ensuring only trusted users or a system administrator can run "modprobe", thereby mitigating the risk of accidental or malicious loading.

Generated by OpenCVE AI on September 19, 2026 at 05:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: cpufreq: amd-pstate-ut: Skip tests when amd-pstate driver is not active The crash issue may occur when modprobe amd_pstate_ut on intel platform. amd_pstate_ut: 1 amd_pstate_ut_acpi_cpc_valid success! amd_pstate_ut: 2 amd_pstate_ut_check_enabled success! BUG: kernel NULL pointer dereference, address: 0000000000000080 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page PGD 0 P4D 0 Oops: 0000 [#1] SMP NOPTI CPU: 0 PID: 20300 Comm: modprobe Kdump: loaded Tainted: G O 6.6.0-0010.rc1.ctl4.x86_64 #1 Hardware name: FiberHome R2200 V5/Xeon Boards, BIOS 3.1a 02/24/2020 RIP: 0010:amd_pstate_ut_check_perf+0x141/0x280 [amd_pstate_ut] Call Trace: <TASK> amd_pstate_ut_init+0x1b/0xff0 [amd_pstate_ut] ? __pfx_amd_pstate_ut_init+0x10/0x10 [amd_pstate_ut] do_one_initcall+0x42/0x2e0 ? kmalloc_trace+0x26/0x90 do_init_module+0x60/0x240 __se_sys_init_module+0x185/0x1c0 do_syscall_64+0x62/0x190 entry_SYSCALL_64_after_hwframe+0x76/0x7e </TASK> Add state detection to amd pstate driver to prevent amd_pstate_ut driver from testing on non-AMD platforms. (ML: adjust title)
Title cpufreq: amd-pstate-ut: Skip tests when amd-pstate driver is not active
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:09.008Z

Reserved: 2026-09-16T12:21:13.871Z

Link: CVE-2026-92493

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:51.443

Modified: 2026-09-17T17:17:51.443

Link: CVE-2026-92493

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T13:15:16Z

Weaknesses