CVE-2026-81013
Received Received - Intake

Heap OOB Read in HP BIOS Configuration Driver

Vulnerability report for CVE-2026-81013, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: fix heap OOB read on empty password write validate_password_input() computes length = strlen(buf) and then checks buf[length - 1] to strip a trailing newline, without checking that length is nonzero first. Writing an empty string (a bare '\n') to current_password or new_password gives length == 0, and buf[length - 1] reads buf[-1], one byte before the heap allocation holding the copied input. KASAN confirms this directly: BUG: KASAN: slab-out-of-bounds in store_password_instance.constprop.0+0x223/0x2a0 [hp_bioscfg] Read of size 1 at addr ffff88811bd8da9f by task sh/13740 ... store_password_instance.constprop.0+0x223/0x2a0 [hp_bioscfg] current_password_store+0x14/0x20 [hp_bioscfg] ... The buggy address is located 23 bytes to the right of allocated 8-byte region [ffff88811bd8da80, ffff88811bd8da88) Reproduced identically via new_password_store. Execution continues past the bad read (the garbage byte only affects whether "length" is decremented by one), so the write completes and returns success; this is a pure information read past the buffer, not a crash, but it is still an out-of-bounds access KASAN correctly flags. Fix by only checking buf[length - 1] when length is nonzero.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-09-30
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hp hp_bioscfg *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a heap out-of-bounds (OOB) read vulnerability in the Linux kernel's hp-bioscfg module. It occurs when writing an empty password string (just a newline character) to current_password or new_password fields. The function validate_password_input calculates the string length and then tries to access the last character without first checking if the string is empty, leading to a read one byte before the allocated heap memory.

Detection Guidance

This vulnerability is specific to the Linux kernel module hp-bioscfg and involves an out-of-bounds read when handling empty password strings. Detection requires checking for the presence of the vulnerable hp-bioscfg module and analyzing kernel logs for KASAN reports indicating slab-out-of-bounds errors related to hp_bioscfg.

Impact Analysis

This vulnerability allows an attacker to read a small amount of memory adjacent to the password buffer. While it does not crash the system or corrupt data, it exposes potentially sensitive information. The impact is limited to information disclosure rather than direct system compromise.

Compliance Impact

This vulnerability involves an out-of-bounds read in the Linux kernel's hp-bioscfg module, which could potentially expose sensitive data. However, the provided context does not specify direct impacts on compliance with standards like GDPR or HIPAA. The issue is a memory access flaw rather than a data breach or unauthorized access scenario typically addressed by these regulations.

Mitigation Strategies

Update the Linux kernel to a patched version that includes the fix for this hp-bioscfg heap OOB read issue. If an update is not immediately available, disable the hp-bioscfg module to prevent exploitation until a patch is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81013. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart