{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90137","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.788Z","datePublished":"2026-09-17T16:06:35.829Z","dateUpdated":"2026-09-18T17:53:17.115Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:53:17.115Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: hp-bioscfg: fix password encoding bounds check\n\nThe password PSWD_ENCODINGS parser reads password_obj[elem + pos_values]\nwhile copying the supported password encodings from the ACPI package.\n\nThe outer loop only guarantees that elem is within password_obj_count.\nThe encoding count is bounded by MAX_ENCODINGS_SIZE, but that does not\nguarantee that the ACPI package contains enough entries for all\nelem + pos_values accesses.\n\nA malformed package can therefore declare a non-zero encoding count\nwithout providing enough string objects, causing the parser to read past\nthe ACPI package array and pass an out-of-bounds string pointer and\nlength to hp_convert_hexstr_to_str().\n\nAdd the same computed-index bounds check used by the other offset-based\npackage parsing loops before reading password_obj[elem + pos_values]."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","baseScore":7.7,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The malformed bytes are the ACPI package from wmi_query_block() on HP_WMI_BIOS_PASSWORD_GUID, walked by hp_populate_password_elements_from_package() during hp_init()/hp_init_bios_attributes(); that is local HP WMI/ACPI firmware data, not a network, Bluetooth/WiFi, or USB protocol message.\nAC:L - A password package whose PSWD_SIZE/encodings_size is non-zero but that lacks encodings_size string objects makes the PSWD_ENCODINGS loop read password_obj[elem+pos_values] past password_obj_count on every probe; firmware sets both the count and the package length, with no race required.\nPR:N - hp_init() calls hp_init_bios_attributes(HPWMI_PASSWORD_TYPE) and hp_populate_password_elements_from_package() with no capable(), credential, or sysfs check; a compromised HP BIOS that returns a short password package triggers the PSWD_ENCODINGS over-read at module init without a Linux user account.\nUI:N - HP_WMI_BIOS_PASSWORD_GUID instances are enumerated automatically in hp_init() when HP_WMI_BIOS_GUID is present (module_init/built-in probe); the victim does not need to write current_password/new_password, mount a filesystem, or take any other action.\nS:U - The over-read is of the kernel heap array obj->package.elements and any oops or copied encodings stay in the same host kernel authority; this WMI password parser is not a KVM/Xen guest-to-host or IOMMU/DMA boundary crossing.\nC:H - Each out-of-bounds slot is treated as string.pointer and string.length and passed to hp_convert_hexstr_to_str(), which kmallocs that length and reads the pointer; the result is strscpy'd into password_data->encodings[] and emitted by the 0444 encodings sysfs show, so the read is not a few bounded bytes.\nI:N - The PSWD_ENCODINGS loop only reads out-of-bounds union acpi_object fields and then 2-argument strscpy()s the conversion into encodings[MAX_ENCODINGS_SIZE][MAX_BUFF_SIZE]; parsed results never write past that fixed array, so there is no OOB write or control-flow hijack primitive.\nA:H - hp_convert_hexstr_to_str() dereferences password_obj[elem+pos_values].string.pointer; an invalid pointer taken from an out-of-bounds ACPI package slot causes a kernel oops or panic while enumerating HP_WMI_BIOS_PASSWORD_GUID instances in hp_init()."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c"],"versions":[{"version":"8646a3b5ee3a5b384a22a721f37c24274d974045","lessThan":"c224759555a13735b0d67561d818cefe00c3309a","status":"affected","versionType":"git"},{"version":"8646a3b5ee3a5b384a22a721f37c24274d974045","lessThan":"59fe8491ddaa03a510b352552e6ee291e7ce45d3","status":"affected","versionType":"git"},{"version":"8646a3b5ee3a5b384a22a721f37c24274d974045","lessThan":"ace1ba5fca0ab775b3641e154bcbc3ccde26a71a","status":"affected","versionType":"git"},{"version":"8646a3b5ee3a5b384a22a721f37c24274d974045","lessThan":"8a7499b8fd34438c1b11964e0e7ef5bd590fec92","status":"affected","versionType":"git"},{"version":"8646a3b5ee3a5b384a22a721f37c24274d974045","lessThan":"e213939ed9e6e6badf7aa48c4c8dd9a9cdf00615","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c"],"versions":[{"version":"6.6","status":"affected"},{"version":"0","lessThan":"6.6","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/c224759555a13735b0d67561d818cefe00c3309a"},{"url":"https://git.kernel.org/stable/c/59fe8491ddaa03a510b352552e6ee291e7ce45d3"},{"url":"https://git.kernel.org/stable/c/ace1ba5fca0ab775b3641e154bcbc3ccde26a71a"},{"url":"https://git.kernel.org/stable/c/8a7499b8fd34438c1b11964e0e7ef5bd590fec92"},{"url":"https://git.kernel.org/stable/c/e213939ed9e6e6badf7aa48c4c8dd9a9cdf00615"}],"title":"platform/x86: hp-bioscfg: fix password encoding bounds check","x_generator":{"engine":"bippy-1.2.0"}}}}