Description
In the Linux kernel, the following vulnerability has been resolved:

platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store()

sk_store() and kek_store() strip a trailing newline from the sysfs
write before allocating the key buffer:

length = count;
if (buf[length - 1] == '\n')
length--;
bioscfg_drv.spm_data.signing_key = kmemdup(buf, length, GFP_KERNEL);

but then pass the original "count" (not "length") as the copy size to
hp_wmi_perform_query(), which memcpy()s that many bytes out of the
"length"-sized allocation, reading one byte past it whenever the write
ends in a newline, the normal case for a shell "echo" into sysfs.

KASAN confirms this directly:

BUG: KASAN: slab-out-of-bounds in hp_wmi_perform_query+0x1e9/0x460 [hp_bioscfg]
Read of size 28 at addr ffff88813c8e2b80 by task python3/16022
...
sk_store+0xa7/0x240 [hp_bioscfg]
kernfs_fop_write_iter+0x3e1/0x5d0
...
The buggy address is located 0 bytes inside of
allocated 27-byte region [ffff88813c8e2b80, ffff88813c8e2b9b)

Reproduced identically for kek_store, and at multiple write sizes
(28, 57, 201 bytes), each time reading exactly one byte past a
kmemdup() allocation one byte smaller than the write.

Fix by passing "length" instead of "count" to hp_wmi_perform_query()
in both functions.
Published: 2026-09-11
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

The flaw is located in the HP BIOS configuration driver of the Linux kernel. When information is written to the driver’s sysfs interface, the code removes a trailing newline and allocates a buffer sized to the trimmed length, but the original write length—including the newline—is passed to hp_wmi_perform_query, which performs a memcpy that reads one byte beyond the allocated buffer. This results in a kernel‑space out‑of‑bounds read that exposes a single byte of kernel memory, providing a modest amount of sensitive information. The vulnerability is classified as CWE‑125.

Affected Systems

Any Linux kernel that includes the hp_bioscfg driver for x86 architectures and has not yet incorporated the patch commit 4c6374dcb270d12907b880cf82a5a5ef21785fc3 is affected. Distributions that ship the module as part of their kernel, such as many mainstream releases on HP or compatible x86 servers and desktops, fall into this category. The vulnerability applies to all kernel versions prior to the patch.

Risk and Exploitability

The base CVSS score is 4.4, the EPSS score is under 1 %, and the vulnerability is not listed in CISA’s KEV catalog. Exploiting the read requires writing to the hp_bioscfg sysfs file. Based on typical kernel configurations, this file is likely writable only by privileged users, so local privilege is probably required to exercise the flaw. Because the leak yields only a single byte and no publicly available exploit exists, the overall risk is likely low to moderate, but this assessment is inferred from the available data. An attacker who already has local privilege could potentially combine the disclosed byte with other techniques to aid further escalation.

Generated by OpenCVE AI on September 21, 2026 at 02:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the fix commit 4c6374dcb270d12907b880cf82a5a5ef21785fc3 or an equivalent patch.
  • If the kernel cannot be updated immediately, consider restricting write permissions on the hp_bioscfg sysfs files to root only (for example, chmod 0600 and chown root:root).
  • If the HP BIOS configuration driver is not required, unload it (modprobe ‑r hp_bioscfg) or disable it permanently via a modprobe blacklist or other kernel module control mechanisms.

Generated by OpenCVE AI on September 21, 2026 at 02:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store() sk_store() and kek_store() strip a trailing newline from the sysfs write before allocating the key buffer: length = count; if (buf[length - 1] == '\n') length--; bioscfg_drv.spm_data.signing_key = kmemdup(buf, length, GFP_KERNEL); but then pass the original "count" (not "length") as the copy size to hp_wmi_perform_query(), which memcpy()s that many bytes out of the "length"-sized allocation, reading one byte past it whenever the write ends in a newline, the normal case for a shell "echo" into sysfs. KASAN confirms this directly: BUG: KASAN: slab-out-of-bounds in hp_wmi_perform_query+0x1e9/0x460 [hp_bioscfg] Read of size 28 at addr ffff88813c8e2b80 by task python3/16022 ... sk_store+0xa7/0x240 [hp_bioscfg] kernfs_fop_write_iter+0x3e1/0x5d0 ... The buggy address is located 0 bytes inside of allocated 27-byte region [ffff88813c8e2b80, ffff88813c8e2b9b) Reproduced identically for kek_store, and at multiple write sizes (28, 57, 201 bytes), each time reading exactly one byte past a kmemdup() allocation one byte smaller than the write. Fix by passing "length" instead of "count" to hp_wmi_perform_query() in both functions.
Title platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T11:59:47.096Z

Reserved: 2026-08-26T14:34:25.813Z

Link: CVE-2026-81014

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:10.297

Modified: 2026-09-14T13:18:55.830

Link: CVE-2026-81014

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:43:03Z

Links: CVE-2026-81014 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T02:15:08Z

Weaknesses