{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2025-71101", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2026-01-13T15:30:19.651Z", "datePublished": "2026-01-13T15:34:59.717Z", "dateUpdated": "2026-08-05T12:12:06.814Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T12:12:06.814Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: hp-bioscfg: Fix out-of-bounds array access in ACPI package parsing\n\nThe hp_populate_*_elements_from_package() functions in the hp-bioscfg\ndriver contain out-of-bounds array access vulnerabilities.\n\nThese functions parse ACPI packages into internal data structures using\na for loop with index variable 'elem' that iterates through\nenum_obj/integer_obj/order_obj/password_obj/string_obj arrays.\n\nWhen processing multi-element fields like PREREQUISITES and\nENUM_POSSIBLE_VALUES, these functions read multiple consecutive array\nelements using expressions like 'enum_obj[elem + reqs]' and\n'enum_obj[elem + pos_values]' within nested loops.\n\nThe bug is that the bounds check only validated elem, but did not consider\nthe additional offset when accessing elem + reqs or elem + pos_values.\n\nThe fix changes the bounds check to validate the actual accessed index." } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H", "baseScore": 7.1, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:L - The vulnerable ACPI/WMI package parsing occurs during local hp-bioscfg initialization, with any resulting disclosure consumed through local sysfs attributes. There is no network, adjacent-radio, or peripheral protocol path.\nAC:L - An inconsistent package count deterministically causes the nested loops to exceed the ACPI element array. No race or condition outside the triggering package and driver configuration is required.\nPR:L - Once hp-bioscfg is initialized, an ordinary local user can read the world-readable sysfs metadata into which enumeration values are copied. No capability, authentication, or user-namespace privilege gate protects that disclosure path.\nUI:N - The driver parses the packages during built-in or module initialization, and exploitation does not require another user to open a file or perform a specific action.\nS:U - The vulnerable parser and the affected kernel memory and availability remain under the same kernel security authority. This is not a guest-to-host escape or another security-boundary crossing.\nC:H - The out-of-bounds descriptors are interpreted as string length and pointer fields, allowing unintended kernel memory to be read and potentially copied into readable enumeration metadata. The read is not strictly bounded to a few bytes.\nI:N - The flaw performs out-of-bounds reads, while parsed results are written through bounded copies into fixed internal arrays. No arbitrary write or control-flow corruption primitive is present.\nA:H - A synthetic or invalid out-of-bounds string pointer can be dereferenced by hp_convert_hexstr_to_str(), causing a kernel fault, oops, or panic during driver initialization." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "drivers/platform/x86/hp/hp-bioscfg/enum-attributes.c", "drivers/platform/x86/hp/hp-bioscfg/int-attributes.c", "drivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c", "drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c", "drivers/platform/x86/hp/hp-bioscfg/string-attributes.c" ], "versions": [ { "version": "e6c7b3e15559699a30646dd45195549c7db447bd", "lessThan": "cf7ae870560b988247a4bbbe5399edd326632680", "status": "affected", "versionType": "git" }, { "version": "e6c7b3e15559699a30646dd45195549c7db447bd", "lessThan": "db4c26adf7117b1a4431d1197ae7109fee3230ad", "status": "affected", "versionType": "git" }, { "version": "e6c7b3e15559699a30646dd45195549c7db447bd", "lessThan": "79cab730dbaaac03b946c7f5681bd08c986e2abd", "status": "affected", "versionType": "git" }, { "version": "e6c7b3e15559699a30646dd45195549c7db447bd", "lessThan": "e44c42c830b7ab36e3a3a86321c619f24def5206", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "drivers/platform/x86/hp/hp-bioscfg/enum-attributes.c", "drivers/platform/x86/hp/hp-bioscfg/int-attributes.c", "drivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c", "drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c", "drivers/platform/x86/hp/hp-bioscfg/string-attributes.c" ], "versions": [ { "version": "6.6", "status": "affected" }, { "version": "0", "lessThan": "6.6", "status": "unaffected", "versionType": "semver" }, { "version": "6.6.120", "lessThanOrEqual": "6.6.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.12.64", "lessThanOrEqual": "6.12.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.18.4", "lessThanOrEqual": "6.18.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.19", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.6", "versionEndExcluding": "6.6.120" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.6", "versionEndExcluding": "6.12.64" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.6", "versionEndExcluding": "6.18.4" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.6", "versionEndExcluding": "6.19" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/cf7ae870560b988247a4bbbe5399edd326632680" }, { "url": "https://git.kernel.org/stable/c/db4c26adf7117b1a4431d1197ae7109fee3230ad" }, { "url": "https://git.kernel.org/stable/c/79cab730dbaaac03b946c7f5681bd08c986e2abd" }, { "url": "https://git.kernel.org/stable/c/e44c42c830b7ab36e3a3a86321c619f24def5206" } ], "title": "platform/x86: hp-bioscfg: Fix out-of-bounds array access in ACPI package parsing", "x_generator": { "engine": "bippy-1.2.0" } } } }