Description
In the Linux kernel, the following vulnerability has been resolved:

platform/x86: hp-bioscfg: fix password encoding bounds check

The password PSWD_ENCODINGS parser reads password_obj[elem + pos_values]
while copying the supported password encodings from the ACPI package.

The outer loop only guarantees that elem is within password_obj_count.
The encoding count is bounded by MAX_ENCODINGS_SIZE, but that does not
guarantee that the ACPI package contains enough entries for all
elem + pos_values accesses.

A malformed package can therefore declare a non-zero encoding count
without providing enough string objects, causing the parser to read past
the ACPI package array and pass an out-of-bounds string pointer and
length to hp_convert_hexstr_to_str().

Add the same computed-index bounds check used by the other offset-based
package parsing loops before reading password_obj[elem + pos_values].
Published: 2026-09-17
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation / Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the Linux kernel’s HP BIOS configuration parser, where a missing bounds check allows a malformed ACPI package to trigger an out‑of‑bounds read of password encoding strings. This can lead to kernel memory corruption and, under the right conditions, arbitrary code execution or privilege escalation. The weakness is characterized by improper input validation and buffer over‑read conditions.

Affected Systems

Any Linux kernel installation that includes the hp-bioscfg module. No specific version was recorded, so the flaw is potentially present in all current kernels until the associated patch is applied.

Risk and Exploitability

The EPSS score is reported as <1%, indicating a low probability of exploitation in the wild. However, the flaw is not listed in the CISA KEV catalog. The exploit path requires delivery of a crafted ACPI package, which could be embedded in firmware updates or supplied via malicious firmware. The CVSS score of 7.7 indicates high severity, making the potential impact significant should the flaw be successfully leveraged.

Generated by OpenCVE AI on September 20, 2026 at 04:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the patch identified by commit 59fe8491ddaa.
  • If an upgrade is not immediately possible, disable the hp-bioscfg subsystem or unload the module to prevent the vulnerable parser from executing.
  • Ensure that BIOS/firmware updates are signed and verified; replace any firmware that may contain malformed ACPI packages with a trusted, patched version.

Generated by OpenCVE AI on September 20, 2026 at 04:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-129
CWE-20

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-125

Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-125

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: fix password encoding bounds check The password PSWD_ENCODINGS parser reads password_obj[elem + pos_values] while copying the supported password encodings from the ACPI package. The outer loop only guarantees that elem is within password_obj_count. The encoding count is bounded by MAX_ENCODINGS_SIZE, but that does not guarantee that the ACPI package contains enough entries for all elem + pos_values accesses. A malformed package can therefore declare a non-zero encoding count without providing enough string objects, causing the parser to read past the ACPI package array and pass an out-of-bounds string pointer and length to hp_convert_hexstr_to_str(). Add the same computed-index bounds check used by the other offset-based package parsing loops before reading password_obj[elem + pos_values].
Title platform/x86: hp-bioscfg: fix password encoding bounds check
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:53:17.115Z

Reserved: 2026-09-11T19:38:34.788Z

Link: CVE-2026-90137

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:06.287

Modified: 2026-09-18T18:17:43.270

Link: CVE-2026-90137

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:30:18Z

Weaknesses
  • CWE-129

    Improper Validation of Array Index

  • CWE-20

    Improper Input Validation