SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-81016

HIGH · CVSS 7.7 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The vulnerability in the Linux kernel affects systems utilizing AMD's System Management Unit (SMU) by failing to properly handle errors from S2D commands, leading to uninitialized physical address values being passed to memory mapping functions. This oversight can result in attempts to map physical address zero, potentially causing system instability or crashes. Organizations using Linux on AMD hardware should prioritize addressing this issue to mitigate risks associated with system reliability and security.

CVE
CVE-2026-81016
Severity
HIGH
CVSS
7.7
EPSS
0.18%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd/pmc: Propagate SMU errors and validate S2D address amd_stb_s2d_init() discards the return value of several S2D SMU commands. When the SMU refuses a command (e.g. "SMU cmd failed. err: 0xff") the failure is only noticed indirectly - if at all - and reported as -EIO, masking the real error. More seriously, the S2D_PHYS_ADDR_LOW/HIGH return values are ignored, so on failure phys_addr_low/hi are left uninitialised and the assembled address is passed straight to devm_ioremap(). When the SMU leaves them at zero this maps physical address 0 and trips the ioremap-on-RAM warning: amd_pmc AMDI000B:00: SMU cmd failed. err: 0xff ioremap on RAM at 0x0000000000000000 - 0x0000000000ffffff WARNING: CPU: 13 PID: 4592 at arch/x86/mm/ioremap.c:... Check the return value of each SMU command and propagate it, and reject a zero physical address before calling devm_ioremap().