← All Advisories

CVE-2026-81015

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-81015

Key Details

CVECVE-2026-81015
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-10-03
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

platform/x86/amd/pmc: Fix LPS0 and debugfs leaks when STB init fails

amd_pmc_probe() registers the LPS0 s2idle handler with

acpi_register_lps0_dev() and creates the driver's debugfs directory before

calling amd_stb_s2d_init(), which is the last step in probe that can fail.

When amd_stb_s2d_init() fails (for example the S2D telemetry region cannot

be ioremapped on a long-running system, or the SMU rejects the S2D setup)

the error path only calls pci_dev_put() and returns. This leaves

amd_pmc_s2idle_dev_ops on the global lps0_s2idle_devops_head list and leaks

the debugfs directory, while the devm-managed resources backing the handler

are torn down.

Reloading the module then walks the corrupted list in

acpi_register_lps0_dev() and hits:

list_add corruption. next->prev should be prev, but was NULL.

kernel BUG at lib/list_debug.c:29!

acpi_register_lps0_dev+0x44/0x80

amd_pmc_probe+0x224/0x380 [amd_pmc]

platform_probe+0x67/0x90

Even without a reload, the stale registration means the next s2idle

transition calls into torn-down driver state.

Unwind the debugfs directory and the LPS0 registration on the

amd_stb_s2d_init() error path. acpi_unregister_lps0_dev() is safe to call

unconditionally here: it is guarded on the same conditions as

acpi_register_lps0_dev(), which is exactly what amd_pmc_remove() already

relies on. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-81015
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-81015