Answer in brief
CVE-2026-81016 records a Unknown severity vulnerability in platform/x86/amd/pmc: Propagate SMU errors and validate S2D address. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=3d7d407dfb05b257e15cb0c6b056428a4a8c2e5d <8178f59d76570b152d836bde07f5997f15861f04 || >=3d7d407dfb05b257e15cb0c6b056428a4a8c2e5d <775d4cde1f9737796ce7d8393521e9e8c5b49891 || >=3d7d407dfb05b257e15cb0c6b056428a4a8c2e5d <0225c1d637687b03726f00ac65b6def843d2c464 | 8178f59d76570b152d836bde07f5997f15861f04, 775d4cde1f9737796ce7d8393521e9e8c5b49891, 0225c1d637687b03726f00ac65b6def843d2c464 |
| Linux/Linuxgeneric | 5.18 | Not reported |
Published upstream
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 11, 2026
In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd/pmc: Propagate SMU errors and validate S2D address amd_stb_s2d_init() discards the return value of several S2D SMU commands. When the SMU refuses a command (e.g. "SMU cmd failed. err: 0xff") the failure is only noticed indirectly - if at all - and reported as -EIO, masking the real error. More seriously, the S2D_PHYS_ADDR_LOW/HIGH return values are ignored, so on failure phys_addr_low/hi are left uninitialised and the assembled address is passed straight to devm_ioremap(). When the SMU leaves them at zero this maps physical address 0 and trips the ioremap-on-RAM warning: amd_pmc AMDI000B:00: SMU cmd failed. err: 0xff ioremap on RAM at 0x0000000000000000 - 0x0000000000ffffff WARNING: CPU: 13 PID: 4592 at arch/x86/mm/ioremap.c:... Check the return value of each SMU command and propagate it, and reject a zero physical address before calling devm_ioremap().
Quoted source text, attributed separately from HOL analysis.