Description
In the Linux kernel, the following vulnerability has been resolved:

platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer()

hp_get_string_from_buffer() clamps the converted string length against
the destination buffer size with "size > dst_size", so when the
converted length is exactly equal to dst_size, conv_dst_size is left
at dst_size and the unconditional NUL terminator write

dst[conv_dst_size] = 0;

lands one byte past the destination buffer. This is the same shape of
bug as the previously fixed off-by-one in hp_convert_hexstr_to_str():
the buffer is sized correctly for the content, but the terminator
write is never checked against that size.

Fix by changing the comparison to ">=" so conv_dst_size is always left
with room for the terminator.

All fixed-size destinations that reach this function (path[512],
current_value[512], current_password/current_value[64], and the
per-entry buffers in encodings[][512] and prerequisites[][512]) are
affected.
Published: 2026-09-11
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption that can lead to crashes or denial of service
Action: Patch
AI Analysis

Impact

In the Linux kernel's hp_get_string_from_buffer function—used by the hp‑bioscfg module to parse HP BIOS configuration strings—there is an off‑by‑one error. The code clamps the converted string length against the destination buffer size with the condition "size > dst_size", which allows the length to equal dst_size. Subsequently, the unconditional NUL terminator is written at dst[conv_dst_size], causing a write one byte beyond the allocated buffer. This buffer overflow (CWE‑193) can corrupt adjacent kernel memory, potentially leading to kernel crashes, denial of service, or, in some contexts, local privilege escalation and memory corruption.

Affected Systems

All Linux kernel builds that contain the hp‑bioscfg module and have not been updated to include the patch are vulnerable. The flaw affects fixed‑size buffers such as path[512], current_value[512], current_password/current_value[64], and the per‑entry arrays encodings[][512] and prerequisites[][512]. Because the hp‑bioscfg module interacts with HP BIOS firmware configuration, any distribution shipping such a kernel will be impacted until the fix is applied.

Risk and Exploitability

The CVSS score of 8.4 reflects the high severity of the buffer overflow, while the EPSS score of less than 1% indicates a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, meaning no known public exploits exist. The attack vector is likely local, requiring an attacker to feed a configuration string of exact buffer length to the hp‑bioscfg interface, which typically requires privileged access to the HP BIOS firmware configuration runtime. Consequently, the risk is high severity but current exposure is low to moderate until a demonstrable exploit is discovered.

Generated by OpenCVE AI on September 21, 2026 at 02:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the hp_get_string_from_buffer fix, such as the latest stable release.
  • If an immediate kernel upgrade is not possible, disable the hp‑bioscfg module or remove the configuration paths that invoke the affected function.
  • Limit or restrict access to the HP BIOS firmware configuration interface to prevent arbitrary string submissions by non‑privileged users.

Generated by OpenCVE AI on September 21, 2026 at 02:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H'}

cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-193
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer() hp_get_string_from_buffer() clamps the converted string length against the destination buffer size with "size > dst_size", so when the converted length is exactly equal to dst_size, conv_dst_size is left at dst_size and the unconditional NUL terminator write dst[conv_dst_size] = 0; lands one byte past the destination buffer. This is the same shape of bug as the previously fixed off-by-one in hp_convert_hexstr_to_str(): the buffer is sized correctly for the content, but the terminator write is never checked against that size. Fix by changing the comparison to ">=" so conv_dst_size is always left with room for the terminator. All fixed-size destinations that reach this function (path[512], current_value[512], current_password/current_value[64], and the per-entry buffers in encodings[][512] and prerequisites[][512]) are affected.
Title platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T11:59:44.954Z

Reserved: 2026-08-26T14:34:25.813Z

Link: CVE-2026-81012

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:10.050

Modified: 2026-09-14T13:18:55.597

Link: CVE-2026-81012

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:43:02Z

Links: CVE-2026-81012 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T02:45:08Z

Weaknesses