Impact
In the Linux kernel's hp_get_string_from_buffer function—used by the hp‑bioscfg module to parse HP BIOS configuration strings—there is an off‑by‑one error. The code clamps the converted string length against the destination buffer size with the condition "size > dst_size", which allows the length to equal dst_size. Subsequently, the unconditional NUL terminator is written at dst[conv_dst_size], causing a write one byte beyond the allocated buffer. This buffer overflow (CWE‑193) can corrupt adjacent kernel memory, potentially leading to kernel crashes, denial of service, or, in some contexts, local privilege escalation and memory corruption.
Affected Systems
All Linux kernel builds that contain the hp‑bioscfg module and have not been updated to include the patch are vulnerable. The flaw affects fixed‑size buffers such as path[512], current_value[512], current_password/current_value[64], and the per‑entry arrays encodings[][512] and prerequisites[][512]. Because the hp‑bioscfg module interacts with HP BIOS firmware configuration, any distribution shipping such a kernel will be impacted until the fix is applied.
Risk and Exploitability
The CVSS score of 8.4 reflects the high severity of the buffer overflow, while the EPSS score of less than 1% indicates a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, meaning no known public exploits exist. The attack vector is likely local, requiring an attacker to feed a configuration string of exact buffer length to the hp‑bioscfg interface, which typically requires privileged access to the HP BIOS firmware configuration runtime. Consequently, the risk is high severity but current exposure is low to moderate until a demonstrable exploit is discovered.
OpenCVE Enrichment
Debian DSA