---
id: CVE-2026-90136
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  platform/x86/amd/hsmp: Reject negative power cap writes in hwmon

  hsmp_hwmon_write() takes the user-supplied hwmon value as a signed long
  and assigns "val / MICROWATT_P…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  platform/x86/amd/hsmp: Reject negative power cap writes in hwmon

  hsmp_hwmon_write() takes the user-supplied hwmon value as a signed long
  and assigns "val / MICROWATT_P…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 92c025db52bb94a032eb3d473bb81e62c19ddbd3 <
    2c09cadec116eba3fdbcb5d8d8641f6777d4a11f
  - >-
    Linux >= 92c025db52bb94a032eb3d473bb81e62c19ddbd3 <
    1b0a3d915320f1600e5ff43f8bc21b73118480b8
  - >-
    Linux >= 92c025db52bb94a032eb3d473bb81e62c19ddbd3 <
    3921bb8635ff2836622df1cdf3194d4f3c1835a4
  - Linux 6.16
published: '2026-09-17'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T17:17:06.173'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90136'
references:
  - url: 'https://git.kernel.org/stable/c/1b0a3d915320f1600e5ff43f8bc21b73118480b8'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/2c09cadec116eba3fdbcb5d8d8641f6777d4a11f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/3921bb8635ff2836622df1cdf3194d4f3c1835a4'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-17T16:21:47.879Z'
epss: 0.00198
epssPercentile: 0.09855
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

platform/x86/amd/hsmp: Reject negative power cap writes in hwmon

hsmp_hwmon_write() takes the user-supplied hwmon value as a signed long
and assigns "val / MICROWATT_PER_MILLIWATT" to msg.args[0], which is a
__u32.  MICROWATT_PER_MILLIWATT is an unsigned long, so a negative write
to power1_cap (e.g. "echo -1 > power1_cap") is first converted to a huge
unsigned value by the division and then stored into the u32 argument.

As a result a nonsensical, multi-gigawatt socket power limit is sent to
the SMU via HSMP_SET_SOCKET_POWER_LIMIT instead of the write being
rejected.

Reject negative values with -EINVAL before the conversion.

Tested with HSMP enabled:

  CAP=$(dirname $(grep -l amd_hsmp_hwmon \
        /sys/class/hwmon/hwmon*/name | head -1))/power1_cap

  # negative write
  echo -1000000 > $CAP ; echo "ret=$?"
  # valid positive write must still work
  echo 400000000 > $CAP ; echo "ret=$?"

Before:
  # echo -1000000 > $CAP ; echo "ret=$?"
  ret=0                             <- accepted; bogus limit sent to SMU
  # echo 400000000 > $CAP ; echo "ret=$?"
  ret=0

After:
  # echo -1000000 > $CAP ; echo "ret=$?"
  bash: echo: write error: Invalid argument
  ret=1                             <- rejected with -EINVAL
  # echo 400000000 > $CAP ; echo "ret=$?"
  ret=0                             <- valid write still works

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
