7.1

CVE-2026-81011

platform/x86: hp-bioscfg: pass validated element count to package parsers

In the Linux kernel, the following vulnerability has been resolved:

platform/x86: hp-bioscfg: pass validated element count to package parsers

The per-type package parsers are handed the wrong element count.

hp_init_bios_package_attribute() validates obj->package.count and then
calls one of the five hp_populate_*_package_data() wrappers (string,
integer, enumeration, ordered list, password). Each wrapper forwards a
count to its hp_populate_*_elements_from_package() parser, but instead
of forwarding the validated obj->package.count it derives the count
from elements[0]. elements[0] is the NAME field and is always an
ACPI_TYPE_STRING, so reading ->package.count from it in fact reads
->string.length through the union acpi_object. The parsers thus bound
themselves against the length of the name string rather than against
the real number of elements in the package.

This is safe today because hp_init_bios_package_attribute() refuses any
package that has fewer than the type's element count, so a parser only
ever runs on a full package and never reads past it regardless of the
bogus bound.

An upcoming change relaxes that check to accept shorter packages. Once
a parser can receive fewer elements than its per-type count, a bound
taken from the name length no longer reflects the array size, and the
"elem < count" loop conditions and "elem + n >= count" sub-loop guards
read past the end of elements[] - an out-of-bounds heap read.

Forward the validated obj->package.count to every *_package_data()
wrapper so the parsers bound themselves against the real package size.
This does not change behaviour for the packages that enumerate
correctly today and is a prerequisite for accepting shorter packages
safely.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version a34fc329b1895fc8a6eb12099adc47009421ba6a
Version < 467e53f231f77a1677191b8cdabdaf1448439d55
Status affected
Version a34fc329b1895fc8a6eb12099adc47009421ba6a
Version < 436017808c7cbcdb5e49b2142090d4391e3de9a6
Status affected
Version a34fc329b1895fc8a6eb12099adc47009421ba6a
Version < a38127df99ae8b1851560b35b837c9952416143a
Status affected
Version a34fc329b1895fc8a6eb12099adc47009421ba6a
Version < 400cbc3ccc88a5ad37cd85056224635ce9eba018
Status affected
Version a34fc329b1895fc8a6eb12099adc47009421ba6a
Version < e0ddfd77c0c320b7d12b6c9169303b140b798775
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.6
Status affected
Version 0
Version < 6.6
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.025
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/436017808c7cbcdb5e49b2142090d4391e3de9a6
https://git.kernel.org/stable/c/a38127df99ae8b1851560b35b837c9952416143a
https://git.kernel.org/stable/c/400cbc3ccc88a5ad37cd85056224635ce9eba018
https://git.kernel.org/stable/c/e0ddfd77c0c320b7d12b6c9169303b140b798775
https://git.kernel.org/stable/c/467e53f231f77a1677191b8cdabdaf1448439d55