CVE-2026-81011
Received Received - Intake

hp-bioscfg Package Parser Element Count Validation Flaw

Vulnerability report for CVE-2026-81011, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: pass validated element count to package parsers The per-type package parsers are handed the wrong element count. hp_init_bios_package_attribute() validates obj->package.count and then calls one of the five hp_populate_*_package_data() wrappers (string, integer, enumeration, ordered list, password). Each wrapper forwards a count to its hp_populate_*_elements_from_package() parser, but instead of forwarding the validated obj->package.count it derives the count from elements[0]. elements[0] is the NAME field and is always an ACPI_TYPE_STRING, so reading ->package.count from it in fact reads ->string.length through the union acpi_object. The parsers thus bound themselves against the length of the name string rather than against the real number of elements in the package. This is safe today because hp_init_bios_package_attribute() refuses any package that has fewer than the type's element count, so a parser only ever runs on a full package and never reads past it regardless of the bogus bound. An upcoming change relaxes that check to accept shorter packages. Once a parser can receive fewer elements than its per-type count, a bound taken from the name length no longer reflects the array size, and the "elem < count" loop conditions and "elem + n >= count" sub-loop guards read past the end of elements[] - an out-of-bounds heap read. Forward the validated obj->package.count to every *_package_data() wrapper so the parsers bound themselves against the real package size. This does not change behaviour for the packages that enumerate correctly today and is a prerequisite for accepting shorter packages safely.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hp linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves incorrect handling of package element counts in the hp-bioscfg driver. The issue occurs when package parsers receive an invalid element count derived from the name string length instead of the actual package size. This can lead to out-of-bounds heap reads if shorter packages are accepted in future changes.

Detection Guidance

This vulnerability is specific to the Linux kernel's hp-bioscfg driver and requires kernel-level inspection. Detection involves checking the kernel version and whether the vulnerable code path exists. Use commands like 'uname -a' to check kernel version and 'modinfo hp-bioscfg' to verify if the module is loaded. If the module is loaded, inspect the kernel logs for related errors.

Impact Analysis

The vulnerability could allow an attacker to read or corrupt kernel memory if they can trigger the affected package parsing. This may lead to system crashes, privilege escalation, or unauthorized data access. However, exploitation requires specific conditions to be met.

Compliance Impact

This vulnerability involves an out-of-bounds heap read in the Linux kernel's hp-bioscfg driver due to incorrect element count validation. It does not directly impact data privacy or security controls required by GDPR or HIPAA, as it is a low-level memory access issue without evidence of data exposure or unauthorized access.

Mitigation Strategies

Update the Linux kernel to a patched version that includes the fix for this vulnerability. Monitor vendor advisories for hp-bioscfg updates. If immediate patching is not possible, consider disabling the hp-bioscfg module if not required, using 'modprobe -r hp-bioscfg'.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81011. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart