๐Ÿ” CVE Alert

CVE-2026-81011

HIGH 7.1

platform/x86: hp-bioscfg: pass validated element count to package parsers

CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: pass validated element count to package parsers The per-type package parsers are handed the wrong element count. hp_init_bios_package_attribute() validates obj->package.count and then calls one of the five hp_populate_*_package_data() wrappers (string, integer, enumeration, ordered list, password). Each wrapper forwards a count to its hp_populate_*_elements_from_package() parser, but instead of forwarding the validated obj->package.count it derives the count from elements[0]. elements[0] is the NAME field and is always an ACPI_TYPE_STRING, so reading ->package.count from it in fact reads ->string.length through the union acpi_object. The parsers thus bound themselves against the length of the name string rather than against the real number of elements in the package. This is safe today because hp_init_bios_package_attribute() refuses any package that has fewer than the type's element count, so a parser only ever runs on a full package and never reads past it regardless of the bogus bound. An upcoming change relaxes that check to accept shorter packages. Once a parser can receive fewer elements than its per-type count, a bound taken from the name length no longer reflects the array size, and the "elem < count" loop conditions and "elem + n >= count" sub-loop guards read past the end of elements[] - an out-of-bounds heap read. Forward the validated obj->package.count to every *_package_data() wrapper so the parsers bound themselves against the real package size. This does not change behaviour for the packages that enumerate correctly today and is a prerequisite for accepting shorter packages safely.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
a34fc329b1895fc8a6eb12099adc47009421ba6a < 467e53f231f77a1677191b8cdabdaf1448439d55 a34fc329b1895fc8a6eb12099adc47009421ba6a < 436017808c7cbcdb5e49b2142090d4391e3de9a6 a34fc329b1895fc8a6eb12099adc47009421ba6a < a38127df99ae8b1851560b35b837c9952416143a a34fc329b1895fc8a6eb12099adc47009421ba6a < 400cbc3ccc88a5ad37cd85056224635ce9eba018 a34fc329b1895fc8a6eb12099adc47009421ba6a < e0ddfd77c0c320b7d12b6c9169303b140b798775
Linux / Linux
6.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/467e53f231f77a1677191b8cdabdaf1448439d55 git.kernel.org: https://git.kernel.org/stable/c/436017808c7cbcdb5e49b2142090d4391e3de9a6 git.kernel.org: https://git.kernel.org/stable/c/a38127df99ae8b1851560b35b837c9952416143a git.kernel.org: https://git.kernel.org/stable/c/400cbc3ccc88a5ad37cd85056224635ce9eba018 git.kernel.org: https://git.kernel.org/stable/c/e0ddfd77c0c320b7d12b6c9169303b140b798775