Impact
The hp‑bioscfg driver in the Linux x86 kernel performs a string length operation on an input buffer and then checks the last character without verifying that the buffer is non‑empty. When an empty string is supplied to current_password or new_password, the code reads from buf[-1], yielding a heap out‑of‑bounds read that exposes a single byte of adjacent memory. The read does not crash the kernel or alter state; it merely leaks a byte that could contain sensitive data.
Affected Systems
Any Linux distribution that ships a kernel containing the unpatched hp‑bioscfg module is affected. No specific kernel version numbers are provided in the CNA data. The vulnerability is present in the generic Linux kernel identifier and applies to all distributions until a kernel containing the upstream patch is deployed.
Risk and Exploitability
The CVSS base score of 4.7 The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. An attacker would need local access to trigger the password write path, such as via a privileged process or BIOS interface that uses the module. While the anomaly can be detected by tools like KASAN, it is silent in normal operation, making it harder to identify on production systems.
OpenCVE Enrichment
Debian DSA