← All Advisories

CVE-2026-81016

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-81016

Key Details

CVECVE-2026-81016
CVSS Score / Version7.7 (High) / CVSS v3.1
Updated2026-10-03
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

platform/x86/amd/pmc: Propagate SMU errors and validate S2D address

amd_stb_s2d_init() discards the return value of several S2D SMU commands.

When the SMU refuses a command (e.g. "SMU cmd failed. err: 0xff") the

failure is only noticed indirectly - if at all - and reported as -EIO,

masking the real error.

More seriously, the S2D_PHYS_ADDR_LOW/HIGH return values are ignored, so

on failure phys_addr_low/hi are left uninitialised and the assembled

address is passed straight to devm_ioremap(). When the SMU leaves them at

zero this maps physical address 0 and trips the ioremap-on-RAM warning:

amd_pmc AMDI000B:00: SMU cmd failed. err: 0xff

ioremap on RAM at 0x0000000000000000 - 0x0000000000ffffff

WARNING: CPU: 13 PID: 4592 at arch/x86/mm/ioremap.c:...

Check the return value of each SMU command and propagate it, and reject a

zero physical address before calling devm_ioremap(). (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-81016
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-81016