-

CVE-2026-81013

platform/x86: hp-bioscfg: fix heap OOB read on empty password write

In the Linux kernel, the following vulnerability has been resolved:

platform/x86: hp-bioscfg: fix heap OOB read on empty password write

validate_password_input() computes length = strlen(buf) and then
checks buf[length - 1] to strip a trailing newline, without checking
that length is nonzero first. Writing an empty string (a bare '\n')
to current_password or new_password gives length == 0, and
buf[length - 1] reads buf[-1], one byte before the heap allocation
holding the copied input.

KASAN confirms this directly:

  BUG: KASAN: slab-out-of-bounds in store_password_instance.constprop.0+0x223/0x2a0 [hp_bioscfg]
  Read of size 1 at addr ffff88811bd8da9f by task sh/13740
  ...
  store_password_instance.constprop.0+0x223/0x2a0 [hp_bioscfg]
  current_password_store+0x14/0x20 [hp_bioscfg]
  ...
  The buggy address is located 23 bytes to the right of
  allocated 8-byte region [ffff88811bd8da80, ffff88811bd8da88)

Reproduced identically via new_password_store. Execution continues
past the bad read (the garbage byte only affects whether "length" is
decremented by one), so the write completes and returns success; this
is a pure information read past the buffer, not a crash, but it is
still an out-of-bounds access KASAN correctly flags.

Fix by only checking buf[length - 1] when length is nonzero.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 8646a3b5ee3a5b384a22a721f37c24274d974045
Version < 21243c15e1d31f0df1517435e3a7784747f19043
Status affected
Version 8646a3b5ee3a5b384a22a721f37c24274d974045
Version < cecb8154bd5fa6c8ddbd1a4e8216bbc0f0eb9828
Status affected
Version 8646a3b5ee3a5b384a22a721f37c24274d974045
Version < 0f9aad08424882dd5714b53d29ae044060890752
Status affected
Version 8646a3b5ee3a5b384a22a721f37c24274d974045
Version < b699e5c1f63a9e79946c35598c8a6f7af2c356b8
Status affected
Version 8646a3b5ee3a5b384a22a721f37c24274d974045
Version < 2b2ec354f905c14e3270e8ec3ab50f7d8ad73bab
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.6
Status affected
Version 0
Version < 6.6
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.078
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/cecb8154bd5fa6c8ddbd1a4e8216bbc0f0eb9828
https://git.kernel.org/stable/c/0f9aad08424882dd5714b53d29ae044060890752
https://git.kernel.org/stable/c/b699e5c1f63a9e79946c35598c8a6f7af2c356b8
https://git.kernel.org/stable/c/2b2ec354f905c14e3270e8ec3ab50f7d8ad73bab
https://git.kernel.org/stable/c/21243c15e1d31f0df1517435e3a7784747f19043