CVE-2025-71101 (GCVE-0-2025-71101)
Vulnerability from cvelistv5
Published
2026-01-13 15:34
Modified
2026-08-05 12:12
Summary
In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: Fix out-of-bounds array access in ACPI package parsing The hp_populate_*_elements_from_package() functions in the hp-bioscfg driver contain out-of-bounds array access vulnerabilities. These functions parse ACPI packages into internal data structures using a for loop with index variable 'elem' that iterates through enum_obj/integer_obj/order_obj/password_obj/string_obj arrays. When processing multi-element fields like PREREQUISITES and ENUM_POSSIBLE_VALUES, these functions read multiple consecutive array elements using expressions like 'enum_obj[elem + reqs]' and 'enum_obj[elem + pos_values]' within nested loops. The bug is that the bounds check only validated elem, but did not consider the additional offset when accessing elem + reqs or elem + pos_values. The fix changes the bounds check to validate the actual accessed index.
Impacted products
Vendor Product Version
Linux Linux Version: e6c7b3e15559699a30646dd45195549c7db447bd
Version: e6c7b3e15559699a30646dd45195549c7db447bd
Version: e6c7b3e15559699a30646dd45195549c7db447bd
Version: e6c7b3e15559699a30646dd45195549c7db447bd
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/platform/x86/hp/hp-bioscfg/enum-attributes.c",
            "drivers/platform/x86/hp/hp-bioscfg/int-attributes.c",
            "drivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c",
            "drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c",
            "drivers/platform/x86/hp/hp-bioscfg/string-attributes.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "cf7ae870560b988247a4bbbe5399edd326632680",
              "status": "affected",
              "version": "e6c7b3e15559699a30646dd45195549c7db447bd",
              "versionType": "git"
            },
            {
              "lessThan": "db4c26adf7117b1a4431d1197ae7109fee3230ad",
              "status": "affected",
              "version": "e6c7b3e15559699a30646dd45195549c7db447bd",
              "versionType": "git"
            },
            {
              "lessThan": "79cab730dbaaac03b946c7f5681bd08c986e2abd",
              "status": "affected",
              "version": "e6c7b3e15559699a30646dd45195549c7db447bd",
              "versionType": "git"
            },
            {
              "lessThan": "e44c42c830b7ab36e3a3a86321c619f24def5206",
              "status": "affected",
              "version": "e6c7b3e15559699a30646dd45195549c7db447bd",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/platform/x86/hp/hp-bioscfg/enum-attributes.c",
            "drivers/platform/x86/hp/hp-bioscfg/int-attributes.c",
            "drivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c",
            "drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c",
            "drivers/platform/x86/hp/hp-bioscfg/string-attributes.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.6"
            },
            {
              "lessThan": "6.6",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.120",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.64",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.4",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.19",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.120",
                  "versionStartIncluding": "6.6",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.64",
                  "versionStartIncluding": "6.6",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.4",
                  "versionStartIncluding": "6.6",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.19",
                  "versionStartIncluding": "6.6",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: hp-bioscfg: Fix out-of-bounds array access in ACPI package parsing\n\nThe hp_populate_*_elements_from_package() functions in the hp-bioscfg\ndriver contain out-of-bounds array access vulnerabilities.\n\nThese functions parse ACPI packages into internal data structures using\na for loop with index variable \u0027elem\u0027 that iterates through\nenum_obj/integer_obj/order_obj/password_obj/string_obj arrays.\n\nWhen processing multi-element fields like PREREQUISITES and\nENUM_POSSIBLE_VALUES, these functions read multiple consecutive array\nelements using expressions like \u0027enum_obj[elem + reqs]\u0027 and\n\u0027enum_obj[elem + pos_values]\u0027 within nested loops.\n\nThe bug is that the bounds check only validated elem, but did not consider\nthe additional offset when accessing elem + reqs or elem + pos_values.\n\nThe fix changes the bounds check to validate the actual accessed index."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerable ACPI/WMI package parsing occurs during local hp-bioscfg initialization, with any resulting disclosure consumed through local sysfs attributes. There is no network, adjacent-radio, or peripheral protocol path.\nAC:L - An inconsistent package count deterministically causes the nested loops to exceed the ACPI element array. No race or condition outside the triggering package and driver configuration is required.\nPR:L - Once hp-bioscfg is initialized, an ordinary local user can read the world-readable sysfs metadata into which enumeration values are copied. No capability, authentication, or user-namespace privilege gate protects that disclosure path.\nUI:N - The driver parses the packages during built-in or module initialization, and exploitation does not require another user to open a file or perform a specific action.\nS:U - The vulnerable parser and the affected kernel memory and availability remain under the same kernel security authority. This is not a guest-to-host escape or another security-boundary crossing.\nC:H - The out-of-bounds descriptors are interpreted as string length and pointer fields, allowing unintended kernel memory to be read and potentially copied into readable enumeration metadata. The read is not strictly bounded to a few bytes.\nI:N - The flaw performs out-of-bounds reads, while parsed results are written through bounded copies into fixed internal arrays. No arbitrary write or control-flow corruption primitive is present.\nA:H - A synthetic or invalid out-of-bounds string pointer can be dereferenced by hp_convert_hexstr_to_str(), causing a kernel fault, oops, or panic during driver initialization."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:12:06.814Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/cf7ae870560b988247a4bbbe5399edd326632680"
        },
        {
          "url": "https://git.kernel.org/stable/c/db4c26adf7117b1a4431d1197ae7109fee3230ad"
        },
        {
          "url": "https://git.kernel.org/stable/c/79cab730dbaaac03b946c7f5681bd08c986e2abd"
        },
        {
          "url": "https://git.kernel.org/stable/c/e44c42c830b7ab36e3a3a86321c619f24def5206"
        }
      ],
      "title": "platform/x86: hp-bioscfg: Fix out-of-bounds array access in ACPI package parsing",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2025-71101",
    "datePublished": "2026-01-13T15:34:59.717Z",
    "dateReserved": "2026-01-13T15:30:19.651Z",
    "dateUpdated": "2026-08-05T12:12:06.814Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…