Impact
The flaw is located in the HP BIOS configuration driver of the Linux kernel. When information is written to the driver’s sysfs interface, the code removes a trailing newline and allocates a buffer sized to the trimmed length, but the original write length—including the newline—is passed to hp_wmi_perform_query, which performs a memcpy that reads one byte beyond the allocated buffer. This results in a kernel‑space out‑of‑bounds read that exposes a single byte of kernel memory, providing a modest amount of sensitive information. The vulnerability is classified as CWE‑125.
Affected Systems
Any Linux kernel that includes the hp_bioscfg driver for x86 architectures and has not yet incorporated the patch commit 4c6374dcb270d12907b880cf82a5a5ef21785fc3 is affected. Distributions that ship the module as part of their kernel, such as many mainstream releases on HP or compatible x86 servers and desktops, fall into this category. The vulnerability applies to all kernel versions prior to the patch.
Risk and Exploitability
The base CVSS score is 4.4, the EPSS score is under 1 %, and the vulnerability is not listed in CISA’s KEV catalog. Exploiting the read requires writing to the hp_bioscfg sysfs file. Based on typical kernel configurations, this file is likely writable only by privileged users, so local privilege is probably required to exercise the flaw. Because the leak yields only a single byte and no publicly available exploit exists, the overall risk is likely low to moderate, but this assessment is inferred from the available data. An attacker who already has local privilege could potentially combine the disclosed byte with other techniques to aid further escalation.
OpenCVE Enrichment
Debian DSA