Junglewise Threat Intelligence

CVE-2026-90137: Linux kernel hp-bioscfg password encoding bounds check

CVE-2026-90137 · Severity: high · CVSS 7.7 · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's HP BIOS configuration driver contains a bug in how it parses password encoding settings from system firmware. An attacker with access to provide malformed firmware data could trigger the driver to read memory beyond its allocated bounds, potentially causing system crashes or other undefined behavior that could affect system stability and security.

Technical details

The vulnerability is an out-of-bounds memory read in the hp-bioscfg driver's PSWD_ENCODINGS parser (platform/x86/hp/hp-bioscfg/passwdobj-attributes.c). The parser iterates through password encodings from an ACPI package, accessing password_obj[elem + pos_values] without verifying that the computed index remains within the bounds of the password_obj_count array. A malformed ACPI package can declare a non-zero encoding count without providing sufficient string entries, causing the parser to read past the array boundary and pass invalid memory pointers to hp_convert_hexstr_to_str(). The fix adds a bounds check (elem + pos_values >= password_obj_count) before each array access. No CVSS vector was provided, but the reported CVSS score is 7.7. The vulnerability affects Linux kernel versions prior to the patch (commit e213939ed9e6e6badf7aa48c4c8dd9a9cdf00615).

Affected products

  • Linux Linux kernel before fix commit e213939ed9e6e6badf7aa48c4c8dd9a9cdf00615

Timeline

  • 2026-09-17: disclosed: CVE-2026-90137 published
  • 2026-09-14: patched: Fix backported to stable branches; original fix commit e213939ed9e6e6badf7aa48c4c8dd9a9cdf00615

References

Related threats