Ad

CVE-2026-81013

NONE EPSS 0.18%
Обновлено 14 сентября 2026
HP
Параметр Значение
Поставщик HP
Публичный эксплойт Нет

В ядре Linux устранена следующая уязвимость: платформа/x86: hp-bioscfg: исправлено чтение кучи OOB при записи пустого пароля validate_password_input() вычисляет длину = strlen(buf), а затем проверяет buf[length - 1] для удаления завершающей новой строки без проверки эта длина сначала не равна нулю. Написание пустой строки (голого '\n') для current_password или new_password дает длину == 0, и buf[длина - 1] читает buf[-1], за один байт до выделения кучи удерживая скопированный ввод. КАСАН подтверждает это прямо: ОШИБКА: KASAN: плита выходит за пределы в store_password_instance.constprop.0+0x223/0x2a0 [hp_bioscfg] Чтение размера 1 по адресу ffff88811bd8da9f с помощью задачи sh/13740. ... store_password_instance.constprop.0+0x223/0x2a0 [hp_bioscfg] current_password_store+0x14/0x20 [hp_bioscfg] ...

Глючный адрес расположен в 23 байтах справа от выделенная 8-байтовая область [ffff88811bd8da80, ffff88811bd8da88) Воспроизводится идентично через new_password_store. Выполнение продолжается после плохого чтения (байт мусора влияет только на то, является ли "длина" уменьшается на единицу), поэтому запись завершается и возвращает успех; это это чистая информация, прочитанная мимо буфера, а не сбой, но это все равно выход за пределы доступа KASAN правильно помечает. Исправьте это, проверив buf[length - 1] только тогда, когда длина не равна нулю.

Показать оригинальное описание (EN)

In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: fix heap OOB read on empty password write validate_password_input() computes length = strlen(buf) and then checks buf[length - 1] to strip a trailing newline, without checking that length is nonzero first. Writing an empty string (a bare '\n') to current_password or new_password gives length == 0, and buf[length - 1] reads buf[-1], one byte before the heap allocation holding the copied input. KASAN confirms this directly: BUG: KASAN: slab-out-of-bounds in store_password_instance.constprop.0+0x223/0x2a0 [hp_bioscfg] Read of size 1 at addr ffff88811bd8da9f by task sh/13740 ... store_password_instance.constprop.0+0x223/0x2a0 [hp_bioscfg] current_password_store+0x14/0x20 [hp_bioscfg] ... The buggy address is located 23 bytes to the right of allocated 8-byte region [ffff88811bd8da80, ffff88811bd8da88) Reproduced identically via new_password_store. Execution continues past the bad read (the garbage byte only affects whether "length" is decremented by one), so the write completes and returns success; this is a pure information read past the buffer, not a crash, but it is still an out-of-bounds access KASAN correctly flags. Fix by only checking buf[length - 1] when length is nonzero.