Description
In the Linux kernel, the following vulnerability has been resolved:

platform/x86: hp-bioscfg: fix heap OOB read on empty password write

validate_password_input() computes length = strlen(buf) and then
checks buf[length - 1] to strip a trailing newline, without checking
that length is nonzero first. Writing an empty string (a bare '\n')
to current_password or new_password gives length == 0, and
buf[length - 1] reads buf[-1], one byte before the heap allocation
holding the copied input.

KASAN confirms this directly:

BUG: KASAN: slab-out-of-bounds in store_password_instance.constprop.0+0x223/0x2a0 [hp_bioscfg]
Read of size 1 at addr ffff88811bd8da9f by task sh/13740
...
store_password_instance.constprop.0+0x223/0x2a0 [hp_bioscfg]
current_password_store+0x14/0x20 [hp_bioscfg]
...
The buggy address is located 23 bytes to the right of
allocated 8-byte region [ffff88811bd8da80, ffff88811bd8da88)

Reproduced identically via new_password_store. Execution continues
past the bad read (the garbage byte only affects whether "length" is
decremented by one), so the write completes and returns success; this
is a pure information read past the buffer, not a crash, but it is
still an out-of-bounds access KASAN correctly flags.

Fix by only checking buf[length - 1] when length is nonzero.
Published: 2026-09-11
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure via Out-of-Bounds Read
Action: Patch Kernel
AI Analysis

Impact

The hp‑bioscfg driver in the Linux x86 kernel performs a string length operation on an input buffer and then checks the last character without verifying that the buffer is non‑empty. When an empty string is supplied to current_password or new_password, the code reads from buf[-1], yielding a heap out‑of‑bounds read that exposes a single byte of adjacent memory. The read does not crash the kernel or alter state; it merely leaks a byte that could contain sensitive data.

Affected Systems

Any Linux distribution that ships a kernel containing the unpatched hp‑bioscfg module is affected. No specific kernel version numbers are provided in the CNA data. The vulnerability is present in the generic Linux kernel identifier and applies to all distributions until a kernel containing the upstream patch is deployed.

Risk and Exploitability

The CVSS base score of 4.7 The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. An attacker would need local access to trigger the password write path, such as via a privileged process or BIOS interface that uses the module. While the anomaly can be detected by tools like KASAN, it is silent in normal operation, making it harder to identify on production systems.

Generated by OpenCVE AI on September 21, 2026 at 02:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the hp‑bioscfg null‑check patch or apply the upstream commit that introduced the check.
  • If the hp‑bioscfg module is not required for BIOS configuration, unload or blacklist it to remove exposure.
  • Ensure any passwords passed to the hp‑bioscfg interface are validated locally to confirm they are non‑empty before invoking the driver.

Generated by OpenCVE AI on September 21, 2026 at 02:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: fix heap OOB read on empty password write validate_password_input() computes length = strlen(buf) and then checks buf[length - 1] to strip a trailing newline, without checking that length is nonzero first. Writing an empty string (a bare '\n') to current_password or new_password gives length == 0, and buf[length - 1] reads buf[-1], one byte before the heap allocation holding the copied input. KASAN confirms this directly: BUG: KASAN: slab-out-of-bounds in store_password_instance.constprop.0+0x223/0x2a0 [hp_bioscfg] Read of size 1 at addr ffff88811bd8da9f by task sh/13740 ... store_password_instance.constprop.0+0x223/0x2a0 [hp_bioscfg] current_password_store+0x14/0x20 [hp_bioscfg] ... The buggy address is located 23 bytes to the right of allocated 8-byte region [ffff88811bd8da80, ffff88811bd8da88) Reproduced identically via new_password_store. Execution continues past the bad read (the garbage byte only affects whether "length" is decremented by one), so the write completes and returns success; this is a pure information read past the buffer, not a crash, but it is still an out-of-bounds access KASAN correctly flags. Fix by only checking buf[length - 1] when length is nonzero.
Title platform/x86: hp-bioscfg: fix heap OOB read on empty password write
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T11:59:46.042Z

Reserved: 2026-08-26T14:34:25.813Z

Link: CVE-2026-81013

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:10.173

Modified: 2026-09-14T13:18:55.720

Link: CVE-2026-81013

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:43:02Z

Links: CVE-2026-81013 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T02:15:08Z

Weaknesses