Impact
The flaw exists in the Linux kernel’s ACPI HP BIOS configuration package parsing on x86 systems. The routine that validates an incoming package’s element count forwards a count derived from the first element—an ACPI string containing the package name—to type‑specific parsers. Because the derivation reads the string’s length instead of the actual number of elements, the parsers base their loop bounds on an unrelated value, which can cause them to read beyond the end of the package buffer, resulting in an out‑of‑bounds read of kernel heap memory. The data read can leak sensitive kernel contents to an attacker who can supply a crafted ACPI package, enabling information disclosure.
Affected Systems
The vulnerability targets the Linux kernel as a whole for the Linux:Linux platform. No specific version range is provided, so any kernel branch that contains the hp-bioscfg parsing code before the commit that corrects the element‑count forwarding may be affected. Distribution maintainers should check whether the commit hash referenced in the provided URLs appears in their kernel sources.
Risk and Exploitability
The likely attack vector involves delivering a malicious ACPI package through firmware updates or exploiting local privilege escalation to manipulate firmware or kernel configuration. The EPSS score of <1% indicates a very low probability of exploitation in the wild, while the CVSS score of 7.1 indicates high severity. This vulnerability is not listed in the CISA KEV catalog. Presently, input validation prevents packages that are too short, but a future relaxation of that check could allow the out-of-bounds read, increasing risk for privileged attackers.
OpenCVE Enrichment
Debian DSA