Unchecked Return Value in Linux kernel - CVE-2026-81016
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to trigger an ioremap-on-RAM warning.
The vulnerability exists due to unchecked return values in amd_stb_s2d_init() when handling S2D SMU physical-address queries. A local user can cause physical address zero to be passed to devm_ioremap() to trigger an ioremap-on-RAM warning.
The condition is associated with the spill-to-DRAM feature's separate SMU message port.