{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-81016","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-26T14:34:25.813Z","datePublished":"2026-09-11T19:43:04.740Z","dateUpdated":"2026-10-03T10:56:24.645Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-03T10:56:24.645Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86/amd/pmc: Propagate SMU errors and validate S2D address\n\namd_stb_s2d_init() discards the return value of several S2D SMU commands.\nWhen the SMU refuses a command (e.g. \"SMU cmd failed. err: 0xff\") the\nfailure is only noticed indirectly - if at all - and reported as -EIO,\nmasking the real error.\n\nMore seriously, the S2D_PHYS_ADDR_LOW/HIGH return values are ignored, so\non failure phys_addr_low/hi are left uninitialised and the assembled\naddress is passed straight to devm_ioremap().  When the SMU leaves them at\nzero this maps physical address 0 and trips the ioremap-on-RAM warning:\n\n  amd_pmc AMDI000B:00: SMU cmd failed. err: 0xff\n  ioremap on RAM at 0x0000000000000000 - 0x0000000000ffffff\n  WARNING: CPU: 13 PID: 4592 at arch/x86/mm/ioremap.c:...\n\nCheck the return value of each SMU command and propagate it, and reject a\nzero physical address before calling devm_ioremap()."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","baseScore":7.7,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - amd_stb_s2d_init() runs from amd_pmc_probe() on the AMD PMC ACPI platform driver (AMDI0005–AMDI000C and related IDs) during local device bind or module load; the SMU mailbox commands and devm_ioremap() are not reachable from network, Bluetooth, Wi-Fi, or USB packet paths.\nAC:L - On affected AMD platforms where SMU accepts S2D_TELEMETRY_SIZE but rejects S2D_PHYS_ADDR_LOW/HIGH (observed err 0xff), ignored failures leave phys_addr_low/hi uninitialized or zero and the subsequent ioremap is deterministic; stack zeroing makes address 0 reliable, with no race or attacker-uncontrollable layout.\nPR:N - The SMU queries and devm_ioremap() execute automatically in amd_pmc_probe() during ACPI/udev bind with no capable() check; enable_stb=1 is the vulnerable STB debug deployment (kernel cmdline or modprobe), after which kernel context runs the path without a user account or namespace privilege.\nUI:N - No victim interaction is required; the invalid ioremap occurs during automatic amd_pmc probe at boot or module load when STB is enabled, before any debugfs open, mount, or other user action.\nS:U - The bad physical-address ioremap, kernel warning, and any subsequent STB debugfs copy occur entirely inside the host kernel PMC driver; this is not a VM escape, IOMMU/DMA boundary bypass, or other cross-authority breakout.\nC:H - Ignored SMU failures pass uninitialized phys_addr_low/hi to devm_ioremap() for up to 16MB (S2D_TELEMETRY_DRAMBYTES_MAX); a non-RAM physical address creates a mapping that amd_stb_debugfs_open_v2 copies to userspace via memcpy_fromio on the 0644 stb_read node, yielding a large physical-memory disclosure.\nI:N - The driver only memcpy_fromio()s the STB mapping and never writes through stb_virt_addr; ioremap of RAM at address 0 is rejected, and there is no out-of-bounds write, use-after-free, or other kernel integrity or control-flow primitive.\nA:H - devm_ioremap() of physical address 0 hits WARN_ONCE in arch/x86/mm/ioremap.c, which panics under panic_on_warn; when the mapping fails, stb_virt_addr stays NULL while debugfs stb_read remains, so a later open does memcpy_fromio(NULL) and oopses the kernel."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/platform/x86/amd/pmc/mp1_stb.c"],"versions":[{"version":"3d7d407dfb05b257e15cb0c6b056428a4a8c2e5d","lessThan":"638e1ca5d4e2b4fdbb209db64926d013b34f3b79","status":"affected","versionType":"git"},{"version":"3d7d407dfb05b257e15cb0c6b056428a4a8c2e5d","lessThan":"8178f59d76570b152d836bde07f5997f15861f04","status":"affected","versionType":"git"},{"version":"3d7d407dfb05b257e15cb0c6b056428a4a8c2e5d","lessThan":"775d4cde1f9737796ce7d8393521e9e8c5b49891","status":"affected","versionType":"git"},{"version":"3d7d407dfb05b257e15cb0c6b056428a4a8c2e5d","lessThan":"0225c1d637687b03726f00ac65b6def843d2c464","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/platform/x86/amd/pmc/mp1_stb.c"],"versions":[{"version":"5.18","status":"affected"},{"version":"0","lessThan":"5.18","status":"unaffected","versionType":"semver"},{"version":"6.12.112","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.18","versionEndExcluding":"6.12.112"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.18","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.18","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.18","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/638e1ca5d4e2b4fdbb209db64926d013b34f3b79"},{"url":"https://git.kernel.org/stable/c/8178f59d76570b152d836bde07f5997f15861f04"},{"url":"https://git.kernel.org/stable/c/775d4cde1f9737796ce7d8393521e9e8c5b49891"},{"url":"https://git.kernel.org/stable/c/0225c1d637687b03726f00ac65b6def843d2c464"}],"title":"platform/x86/amd/pmc: Propagate SMU errors and validate S2D address","x_generator":{"engine":"bippy-1.2.0"}}}}