Impact
The vulnerability resides in the Linux kernel’s HP BIOS configuration parser, where a missing bounds check allows a malformed ACPI package to trigger an out‑of‑bounds read of password encoding strings. This can lead to kernel memory corruption and, under the right conditions, arbitrary code execution or privilege escalation. The weakness is characterized by improper input validation and buffer over‑read conditions.
Affected Systems
Any Linux kernel installation that includes the hp-bioscfg module. No specific version was recorded, so the flaw is potentially present in all current kernels until the associated patch is applied.
Risk and Exploitability
The EPSS score is reported as <1%, indicating a low probability of exploitation in the wild. However, the flaw is not listed in the CISA KEV catalog. The exploit path requires delivery of a crafted ACPI package, which could be embedded in firmware updates or supplied via malicious firmware. The CVSS score of 7.7 indicates high severity, making the potential impact significant should the flaw be successfully leveraged.
OpenCVE Enrichment
Debian DLA
Debian DSA