CVE-2026-81016
Received Received - Intake

SMU Command Failure in Linux Kernel

Vulnerability report for CVE-2026-81016, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-13

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd/pmc: Propagate SMU errors and validate S2D address amd_stb_s2d_init() discards the return value of several S2D SMU commands. When the SMU refuses a command (e.g. "SMU cmd failed. err: 0xff") the failure is only noticed indirectly - if at all - and reported as -EIO, masking the real error. More seriously, the S2D_PHYS_ADDR_LOW/HIGH return values are ignored, so on failure phys_addr_low/hi are left uninitialised and the assembled address is passed straight to devm_ioremap(). When the SMU leaves them at zero this maps physical address 0 and trips the ioremap-on-RAM warning: amd_pmc AMDI000B:00: SMU cmd failed. err: 0xff ioremap on RAM at 0x0000000000000000 - 0x0000000000ffffff WARNING: CPU: 13 PID: 4592 at arch/x86/mm/ioremap.c:... Check the return value of each SMU command and propagate it, and reject a zero physical address before calling devm_ioremap().

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-13
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
amd linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves improper handling of SMU commands in the AMD PMC driver. The function amd_stb_s2d_init() ignores return values from S2D SMU commands, masking real errors and returning -EIO instead. Additionally, it fails to validate the S2D_PHYS_ADDR_LOW/HIGH return values, leaving physical address variables uninitialized. This can lead to mapping physical address 0, triggering a kernel warning.

Detection Guidance

This vulnerability is specific to the Linux kernel's AMD PMC driver and may not have direct network detection methods. Check kernel logs for errors like 'SMU cmd failed' or 'ioremap on RAM' warnings. Use 'dmesg | grep -i amd_pmc' or 'journalctl -k | grep -i amd_pmc' to inspect system logs for these indicators.

Impact Analysis

This vulnerability could cause system instability or crashes due to incorrect memory mapping. It may also lead to silent failures where errors are not properly reported, making troubleshooting difficult. In worst cases, it could allow unauthorized access to sensitive memory regions if physical address 0 is incorrectly mapped.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards. It is a low-level Linux kernel issue related to error handling in AMD PMC (Platform Management Controller) driver code, which could lead to system instability or crashes but does not involve data exposure or privacy violations.

Mitigation Strategies

Update the Linux kernel to the latest stable version that includes the fix for this vulnerability. Monitor kernel logs for SMU command failures or ioremap warnings. If using an affected kernel version, apply the patch from the Linux kernel source or vendor updates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81016. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart