Junglewise Threat Intelligence

CVE-2026-92493: Linux kernel amd-pstate-ut NULL pointer dereference on non-AMD platforms

CVE-2026-92493 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The AMD P-State CPU frequency scaling test module crashes with a NULL pointer dereference when loaded on Intel platforms. The test suite was attempting to access AMD-specific hardware state without first verifying the AMD P-State driver was active, causing kernel panics on incompatible systems. This fix prevents the test module from running on non-AMD platforms, eliminating the crash.

Technical details

The vulnerability is a NULL pointer dereference in the amd-pstate-ut test module's initialization code. When the amd_pstate_ut kernel module is loaded via modprobe on Intel platforms where the amd-pstate driver is not active, the amd_pstate_ut_check_perf() function attempts to dereference uninitialized or NULL pointers in AMD-specific data structures. The fix adds a state detection check in amd_pstate_ut_init() that calls amd_pstate_get_status() and returns -EOPNOTSUPP if the driver is in UNDEFINED or DISABLED state, preventing test execution on non-AMD systems. This is a defensive coding improvement rather than a remotely exploitable security vulnerability, as it requires local access to load kernel modules.

Affected products

  • Linux Linux kernel 6.6.0 and earlier versions with amd-pstate-ut module

Timeline

  • 2026-09-17: disclosed
  • 2026-07-22: patched: Fix committed upstream

References

Related threats