CVE-2026-90136

Source
https://cve.org/CVERecord?id=CVE-2026-90136
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90136.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90136
Downstream
Published
2026-09-17T16:06:35Z
Modified
2026-09-18T03:48:35Z
Summary
platform/x86/amd/hsmp: Reject negative power cap writes in hwmon
Details

In the Linux kernel, the following vulnerability has been resolved:

platform/x86/amd/hsmp: Reject negative power cap writes in hwmon

hsmp_hwmon_write() takes the user-supplied hwmon value as a signed long and assigns "val / MICROWATT_PER_MILLIWATT" to msg.args[0], which is a __u32. MICROWATT_PER_MILLIWATT is an unsigned long, so a negative write to power1_cap (e.g. "echo -1 > power1_cap") is first converted to a huge unsigned value by the division and then stored into the u32 argument.

As a result a nonsensical, multi-gigawatt socket power limit is sent to the SMU via HSMP_SET_SOCKET_POWER_LIMIT instead of the write being rejected.

Reject negative values with -EINVAL before the conversion.

Tested with HSMP enabled:

CAP=$(dirname $(grep -l amd_hsmp_hwmon
/sys/class/hwmon/hwmon*/name | head -1))/power1_cap

negative write

echo -1000000 > $CAP ; echo "ret=$?"

valid positive write must still work

echo 400000000 > $CAP ; echo "ret=$?"

Before:

echo -1000000 > $CAP ; echo "ret=$?"

ret=0 <- accepted; bogus limit sent to SMU

echo 400000000 > $CAP ; echo "ret=$?"

ret=0

After:

echo -1000000 > $CAP ; echo "ret=$?"

bash: echo: write error: Invalid argument ret=1 <- rejected with -EINVAL

echo 400000000 > $CAP ; echo "ret=$?"

ret=0 <- valid write still works

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90136.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
92c025db52bb94a032eb3d473bb81e62c19ddbd3
Fixed
2c09cadec116eba3fdbcb5d8d8641f6777d4a11f
Fixed
1b0a3d915320f1600e5ff43f8bc21b73118480b8
Fixed
3921bb8635ff2836622df1cdf3194d4f3c1835a4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90136.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.16.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90136.json"