{"id":"CVE-2026-81011","title":"kernel: platform/x86: hp-bioscfg: pass validated element count to package parsers (CVE-2026-81011)","summary":"A flaw was found in the Linux kernel's hp-bioscfg module. The module's package parsers incorrectly determine the number of elements in a package, using a value derived from a name string rather than the true package size. While currently p…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-125","vendor":"Red Hat","product":"Linux","affected":["Linux >= a34fc329b1895fc8a6eb12099adc47009421ba6a < 467e53f231f77a1677191b8cdabdaf1448439d55","Linux >= a34fc329b1895fc8a6eb12099adc47009421ba6a < 436017808c7cbcdb5e49b2142090d4391e3de9a6","Linux >= a34fc329b1895fc8a6eb12099adc47009421ba6a < a38127df99ae8b1851560b35b837c9952416143a","Linux >= a34fc329b1895fc8a6eb12099adc47009421ba6a < 400cbc3ccc88a5ad37cd85056224635ce9eba018","Linux >= a34fc329b1895fc8a6eb12099adc47009421ba6a < e0ddfd77c0c320b7d12b6c9169303b140b798775","Linux 6.6"],"published":"2026-09-11","updated":"2026-09-14","sourceUpdated":"2026-09-14T21:17:47+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81011.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81011.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-81011"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532502"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-81011"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81011"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-81011.mbox"},{"url":"https://git.kernel.org/stable/c/467e53f231f77a1677191b8cdabdaf1448439d55"},{"url":"https://git.kernel.org/stable/c/436017808c7cbcdb5e49b2142090d4391e3de9a6"},{"url":"https://git.kernel.org/stable/c/a38127df99ae8b1851560b35b837c9952416143a"},{"url":"https://git.kernel.org/stable/c/400cbc3ccc88a5ad37cd85056224635ce9eba018"},{"url":"https://git.kernel.org/stable/c/e0ddfd77c0c320b7d12b6c9169303b140b798775"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.00166,"epssPercentile":0.05138,"scores":{"vendor":5.5,"cna":7.1},"ingestedAt":"2026-09-14T15:23:07.454Z","slug":"CVE-2026-81011","body":"## Overview\n\nA flaw was found in the Linux kernel's hp-bioscfg module. The module's package parsers incorrectly determine the number of elements in a package, using a value derived from a name string rather than the true package size. While currently prevented by existing validation, a future change to the kernel will allow shorter packages, enabling a local attacker to craft a malicious package. This could result in an out-of-bounds heap read, potentially leading to information disclosure or system instability.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81011.json)\n\n**kernel: platform/x86: hp-bioscfg: pass validated element count to package parsers** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-14.\n\nNot affected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nRefer to the advisory for fix availability.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":204134,"id":"CVE-2026-81011","ts":1789490231951,"field":"cvss","old":"7.1","new":"5.5"},{"seq":204133,"id":"CVE-2026-81011","ts":1789490231951,"field":"severity","old":"high","new":"medium"},{"seq":183562,"id":"CVE-2026-81011","ts":1789356675895,"field":"cvss","old":"7.1","new":"4.7"},{"seq":183561,"id":"CVE-2026-81011","ts":1789356675895,"field":"severity","old":"high","new":"medium"},{"seq":153208,"id":"CVE-2026-81011","ts":1789285349553,"field":"cvss","old":null,"new":"7.1"},{"seq":153207,"id":"CVE-2026-81011","ts":1789285349553,"field":"severity","old":"none","new":"high"},{"seq":147103,"id":"CVE-2026-81011","ts":1789270195183,"field":"cvss","old":null,"new":"4.7"},{"seq":147102,"id":"CVE-2026-81011","ts":1789270195183,"field":"severity","old":"none","new":"medium"},{"seq":108864,"id":"CVE-2026-81011","ts":1789183729310,"field":"cvss","old":null,"new":"4.7"},{"seq":108863,"id":"CVE-2026-81011","ts":1789183729310,"field":"severity","old":"none","new":"medium"}]}