PT-2026-90142 · Linux · Linux
CVE-2026-81012
·
Published
2026-09-11
·
Updated
2026-09-11
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
platform/x86: hp-bioscfg: fix off-by-one write in hp get string from buffer()
hp get string from buffer() clamps the converted string length against
the destination buffer size with "size > dst size", so when the
converted length is exactly equal to dst size, conv dst size is left
at dst size and the unconditional NUL terminator write
dst[conv dst size] = 0;lands one byte past the destination buffer. This is the same shape of
bug as the previously fixed off-by-one in hp convert hexstr to str():
the buffer is sized correctly for the content, but the terminator
write is never checked against that size.
Fix by changing the comparison to ">=" so conv dst size is always left
with room for the terminator.
All fixed-size destinations that reach this function (path[512],
current value[512], current password/current value[64], and the
per-entry buffers in encodings[][512] and prerequisites[][512]) are
affected.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux