CVE-2026-90136
In the Linux kernel, the following vulnerability has been resolved:
platform/x86/amd/hsmp: Reject negative power cap writes in hwmon
hsmp_hwmon_write() takes the user-supplied hwmon value as a signed long and assigns "val / MICROWATT_PER_MILLIWATT" to msg.args[0], which is a __u32. MICROWATT_PER_MILLIWATT is an unsigned long, so a negative write to power1_cap (e.g. "echo -1 > power1_cap") is first converted to a huge unsigned value by the division and then stored into the u32 argument.
As a result a nonsensical, multi-gigawatt socket power limit is sent to the SMU via HSMP_SET_SOCKET_POWER_LIMIT instead of the write being rejected.
Leer descripción completaMostrar menos
Reject negative values with -EINVAL before the conversion.
Tested with HSMP enabled:
Detalles técnicos trazas, registros y código del informe original
CAP=$(dirname $(grep -l amd_hsmp_hwmon \
/sys/class/hwmon/hwmon*/name | head -1))/power1_cap
# negative write
echo -1000000 > $CAP ; echo "ret=$?"
# valid positive write must still work
echo 400000000 > $CAP ; echo "ret=$?"
Before:
# echo -1000000 > $CAP ; echo "ret=$?"
ret=0 <- accepted; bogus limit sent to SMU
# echo 400000000 > $CAP ; echo "ret=$?"
ret=0
After:
# echo -1000000 > $CAP ; echo "ret=$?"
bash: echo: write error: Invalid argument
ret=1 <- rejected with -EINVAL
# echo 400000000 > $CAP ; echo "ret=$?"
ret=0 <- valid write still worksCVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-90136",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "92c025db52bb94a032eb3d473bb81e62c19ddbd3",
"lessThan": "2c09cadec116eba3fdbcb5d8d8641f6777d4a11f",
"versionType": "git"
},
{
"status": "affected",
"version": "92c025db52bb94a032eb3d473bb81e62c19ddbd3",
"lessThan": "1b0a3d915320f1600e5ff43f8bc21b73118480b8",
"versionType": "git"
},
{
"status": "affected",
"version": "92c025db52bb94a032eb3d473bb81e62c19ddbd3",
"lessThan": "3921bb8635ff2836622df1cdf3194d4f3c1835a4",
"versionType": "git"
}
],
"programFiles": [
"drivers/platform/x86/amd/hsmp/hwmon.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.16"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.16",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.18.52",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.6",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/platform/x86/amd/hsmp/hwmon.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-17T17:17:06.173",
"references": [
{
"url": "https://git.kernel.org/stable/c/1b0a3d915320f1600e5ff43f8bc21b73118480b8",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/2c09cadec116eba3fdbcb5d8d8641f6777d4a11f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/3921bb8635ff2836622df1cdf3194d4f3c1835a4",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86/amd/hsmp: Reject negative power cap writes in hwmon\n\nhsmp_hwmon_write() takes the user-supplied hwmon value as a signed long\nand assigns \"val / MICROWATT_PER_MILLIWATT\" to msg.args[0], which is a\n__u32. MICROWATT_PER_MILLIWATT is an unsigned long, so a negative write\nto power1_cap (e.g. \"echo -1 > power1_cap\") is first converted to a huge\nunsigned value by the division and then stored into the u32 argument.\n\nAs a result a nonsensical, multi-gigawatt socket power limit is sent to\nthe SMU via HSMP_SET_SOCKET_POWER_LIMIT instead of the write being\nrejected.\n\nReject negative values with -EINVAL before the conversion.\n\nTested with HSMP enabled:\n\n CAP=$(dirname $(grep -l amd_hsmp_hwmon \\\n /sys/class/hwmon/hwmon*/name | head -1))/power1_cap\n\n # negative write\n echo -1000000 > $CAP ; echo \"ret=$?\"\n # valid positive write must still work\n echo 400000000 > $CAP ; echo \"ret=$?\"\n\nBefore:\n # echo -1000000 > $CAP ; echo \"ret=$?\"\n ret=0 <- accepted; bogus limit sent to SMU\n # echo 400000000 > $CAP ; echo \"ret=$?\"\n ret=0\n\nAfter:\n # echo -1000000 > $CAP ; echo \"ret=$?\"\n bash: echo: write error: Invalid argument\n ret=1 <- rejected with -EINVAL\n # echo 400000000 > $CAP ; echo \"ret=$?\"\n ret=0 <- valid write still works"
}
],
"lastModified": "2026-09-17T17:17:06.173",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}