8.4

CVE-2026-81012

platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer()

In the Linux kernel, the following vulnerability has been resolved:

platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer()

hp_get_string_from_buffer() clamps the converted string length against
the destination buffer size with "size > dst_size", so when the
converted length is exactly equal to dst_size, conv_dst_size is left
at dst_size and the unconditional NUL terminator write

	dst[conv_dst_size] = 0;

lands one byte past the destination buffer. This is the same shape of
bug as the previously fixed off-by-one in hp_convert_hexstr_to_str():
the buffer is sized correctly for the content, but the terminator
write is never checked against that size.

Fix by changing the comparison to ">=" so conv_dst_size is always left
with room for the terminator.

All fixed-size destinations that reach this function (path[512],
current_value[512], current_password/current_value[64], and the
per-entry buffers in encodings[][512] and prerequisites[][512]) are
affected.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version a34fc329b1895fc8a6eb12099adc47009421ba6a
Version < 8f5aa1506cdddea6b33584c2445b9ce99eeddb64
Status affected
Version a34fc329b1895fc8a6eb12099adc47009421ba6a
Version < 3cc772d0154799961f032e5a992d4a50523e291a
Status affected
Version a34fc329b1895fc8a6eb12099adc47009421ba6a
Version < b15b334fbc3c0c46440f8a892ebf62164fca23d6
Status affected
Version a34fc329b1895fc8a6eb12099adc47009421ba6a
Version < ddf98cf33529714b3ba1a158afb1db5b0f759a1a
Status affected
Version a34fc329b1895fc8a6eb12099adc47009421ba6a
Version < dc03f05e419f3460342fb7564884f244622634b6
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.6
Status affected
Version 0
Version < 6.6
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.04
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.4 2.5 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/3cc772d0154799961f032e5a992d4a50523e291a
https://git.kernel.org/stable/c/b15b334fbc3c0c46440f8a892ebf62164fca23d6
https://git.kernel.org/stable/c/ddf98cf33529714b3ba1a158afb1db5b0f759a1a
https://git.kernel.org/stable/c/dc03f05e419f3460342fb7564884f244622634b6
https://git.kernel.org/stable/c/8f5aa1506cdddea6b33584c2445b9ce99eeddb64