Executive brief
The Linux kernel's HP BIOS configuration driver contains a bug in how it parses password encoding settings from system firmware. An attacker with access to provide malformed firmware data could trigger the driver to read memory beyond its allocated bounds, potentially causing system crashes or other undefined behavior that could affect system stability and security.
Technical details
The vulnerability is an out-of-bounds memory read in the hp-bioscfg driver's PSWD_ENCODINGS parser (platform/x86/hp/hp-bioscfg/passwdobj-attributes.c). The parser iterates through password encodings from an ACPI package, accessing password_obj[elem + pos_values] without verifying that the computed index remains within the bounds of the password_obj_count array. A malformed ACPI package can declare a non-zero encoding count without providing sufficient string entries, causing the parser to read past the array boundary and pass invalid memory pointers to hp_convert_hexstr_to_str(). The fix adds a bounds check (elem + pos_values >= password_obj_count) before each array access. No CVSS vector was provided, but the reported CVSS score is 7.7. The vulnerability affects Linux kernel versions prior to the patch (commit e213939ed9e6e6badf7aa48c4c8dd9a9cdf00615).
Affected products
- Linux Linux kernel before fix commit e213939ed9e6e6badf7aa48c4c8dd9a9cdf00615
Timeline
- 2026-09-17: disclosed: CVE-2026-90137 published
- 2026-09-14: patched: Fix backported to stable branches; original fix commit e213939ed9e6e6badf7aa48c4c8dd9a9cdf00615