Impact
The hp‑bioscfg driver in the Linux x86 password the last character without verifying the string is non‑empty. When a password value consists only of a newline or is empty, the code reads from buf[-1], producing a heap out‑of‑bounds read that can expose adjacent memory contents. The error does not crash the kernel or alter its state; it simply leaks a single byte that may contain sensitive data. This constitutes a pure information leakage vulnerability rather than a denial‑of‑service or remote execution flaw.
Affected Systems
Any Linux distribution that ships a kernel containing the unpatched hp‑bioscfg module is affected. The vulnerability is present in the generic the universal CPE and vendor, before the patch are vulnerable.
Risk and Exploitability
The CVSS base score of 4.7 reflects moderate severity. The EPSS score of 0.18% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. An attacker would need local access to trigger the password write path, such as via a privileged process or BIOS interface that uses the module. While the anomaly can be detected by tools like KASAN, it is silent in normal operation, making it harder to identify on production systems.
OpenCVE Enrichment