{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-81012","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-26T14:34:25.813Z","datePublished":"2026-09-11T19:43:02.082Z","dateUpdated":"2026-09-14T11:59:44.954Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T11:59:44.954Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer()\n\nhp_get_string_from_buffer() clamps the converted string length against\nthe destination buffer size with \"size > dst_size\", so when the\nconverted length is exactly equal to dst_size, conv_dst_size is left\nat dst_size and the unconditional NUL terminator write\n\n\tdst[conv_dst_size] = 0;\n\nlands one byte past the destination buffer. This is the same shape of\nbug as the previously fixed off-by-one in hp_convert_hexstr_to_str():\nthe buffer is sized correctly for the content, but the terminator\nwrite is never checked against that size.\n\nFix by changing the comparison to \">=\" so conv_dst_size is always left\nwith room for the terminator.\n\nAll fixed-size destinations that reach this function (path[512],\ncurrent_value[512], current_password/current_value[64], and the\nper-entry buffers in encodings[][512] and prerequisites[][512]) are\naffected."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - hp_get_string_from_buffer() runs during local hp-bioscfg initialization while parsing HP WMI/ACPI BIOS attribute buffers from wmi_query_block(); there is no network, Bluetooth, or USB protocol path into this UTF-16 conversion.\nAC:L - A WMI buffer whose converted string length equals the destination size deterministically writes the NUL terminator one byte past the buffer; firmware controls the length prefix and contents, with no race or attacker-uncontrollable layout required to trigger the overflow.\nPR:N - The overflow executes automatically in hp_init()/hp_init_bios_attributes() while parsing firmware-supplied WMI buffers, with no Linux user account, capability, or sysfs check on that path; a supply-chain or compromised HP BIOS suffices.\nUI:N - Every WMI BIOS attribute instance is parsed automatically at boot or module load; exploitation does not require a victim to mount a filesystem, open a file, or take any other action.\nS:U - The out-of-bounds write corrupts kernel heap or stack in the same host kernel security authority and does not cross a VM, IOMMU, or sandbox boundary.\nC:H - The one-byte overflow past heap objects (including a kcalloc buffer sized from the remaining WMI payload) and kernel-stack name buffers corrupts adjacent objects or pointer LSBs, which is leverageable for kernel memory disclosure.\nI:H - This is an out-of-bounds write past fixed-size fields and a separately allocated heap buffer whose size is chosen from the firmware buffer length, giving a slab-adjacent write primitive usable for control-flow hijacking after heap grooming.\nA:H - Writing one byte past a kmalloc object or kernel stack buffer can corrupt adjacent pointers or slab metadata and cause a kernel oops, KASAN abort, or panic during hp-bioscfg bring-up."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/platform/x86/hp/hp-bioscfg/bioscfg.c"],"versions":[{"version":"a34fc329b1895fc8a6eb12099adc47009421ba6a","lessThan":"8f5aa1506cdddea6b33584c2445b9ce99eeddb64","status":"affected","versionType":"git"},{"version":"a34fc329b1895fc8a6eb12099adc47009421ba6a","lessThan":"3cc772d0154799961f032e5a992d4a50523e291a","status":"affected","versionType":"git"},{"version":"a34fc329b1895fc8a6eb12099adc47009421ba6a","lessThan":"b15b334fbc3c0c46440f8a892ebf62164fca23d6","status":"affected","versionType":"git"},{"version":"a34fc329b1895fc8a6eb12099adc47009421ba6a","lessThan":"ddf98cf33529714b3ba1a158afb1db5b0f759a1a","status":"affected","versionType":"git"},{"version":"a34fc329b1895fc8a6eb12099adc47009421ba6a","lessThan":"dc03f05e419f3460342fb7564884f244622634b6","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/platform/x86/hp/hp-bioscfg/bioscfg.c"],"versions":[{"version":"6.6","status":"affected"},{"version":"0","lessThan":"6.6","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/8f5aa1506cdddea6b33584c2445b9ce99eeddb64"},{"url":"https://git.kernel.org/stable/c/3cc772d0154799961f032e5a992d4a50523e291a"},{"url":"https://git.kernel.org/stable/c/b15b334fbc3c0c46440f8a892ebf62164fca23d6"},{"url":"https://git.kernel.org/stable/c/ddf98cf33529714b3ba1a158afb1db5b0f759a1a"},{"url":"https://git.kernel.org/stable/c/dc03f05e419f3460342fb7564884f244622634b6"}],"title":"platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer()","x_generator":{"engine":"bippy-1.2.0"}}}}