-

CVE-2026-81014

platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store()

In the Linux kernel, the following vulnerability has been resolved:

platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store()

sk_store() and kek_store() strip a trailing newline from the sysfs
write before allocating the key buffer:

	length = count;
	if (buf[length - 1] == '\n')
		length--;
	bioscfg_drv.spm_data.signing_key = kmemdup(buf, length, GFP_KERNEL);

but then pass the original "count" (not "length") as the copy size to
hp_wmi_perform_query(), which memcpy()s that many bytes out of the
"length"-sized allocation, reading one byte past it whenever the write
ends in a newline, the normal case for a shell "echo" into sysfs.

KASAN confirms this directly:

  BUG: KASAN: slab-out-of-bounds in hp_wmi_perform_query+0x1e9/0x460 [hp_bioscfg]
  Read of size 28 at addr ffff88813c8e2b80 by task python3/16022
  ...
  sk_store+0xa7/0x240 [hp_bioscfg]
  kernfs_fop_write_iter+0x3e1/0x5d0
  ...
  The buggy address is located 0 bytes inside of
  allocated 27-byte region [ffff88813c8e2b80, ffff88813c8e2b9b)

Reproduced identically for kek_store, and at multiple write sizes
(28, 57, 201 bytes), each time reading exactly one byte past a
kmemdup() allocation one byte smaller than the write.

Fix by passing "length" instead of "count" to hp_wmi_perform_query()
in both functions.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version b2715aa2e1352c0060b9dcba57a2e465bbfbcd68
Version < 81db79fed115640736188e56595b1e9aec317d5b
Status affected
Version b2715aa2e1352c0060b9dcba57a2e465bbfbcd68
Version < 4c6374dcb270d12907b880cf82a5a5ef21785fc3
Status affected
Version b2715aa2e1352c0060b9dcba57a2e465bbfbcd68
Version < 7cd8fe01aba303a2382db0966eb6c8ab41d5f3c2
Status affected
Version b2715aa2e1352c0060b9dcba57a2e465bbfbcd68
Version < 67b60703d7d8af1ca0e49f72e1bdb1ccecd41b5b
Status affected
Version b2715aa2e1352c0060b9dcba57a2e465bbfbcd68
Version < a7508c7959ff8d037327d377ed21a9c0eabe4674
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.6
Status affected
Version 0
Version < 6.6
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.063
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/4c6374dcb270d12907b880cf82a5a5ef21785fc3
https://git.kernel.org/stable/c/7cd8fe01aba303a2382db0966eb6c8ab41d5f3c2
https://git.kernel.org/stable/c/67b60703d7d8af1ca0e49f72e1bdb1ccecd41b5b
https://git.kernel.org/stable/c/a7508c7959ff8d037327d377ed21a9c0eabe4674
https://git.kernel.org/stable/c/81db79fed115640736188e56595b1e9aec317d5b