{"id":"CVE-2026-81014","title":"kernel: platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store() (CVE-2026-81014)","summary":"A flaw was found in the Linux kernel's `hp-bioscfg` module. A local attacker with write access to the `sysfs` entry for `hp-bioscfg` could exploit a heap out-of-bounds read vulnerability. This occurs because the `sk_store()` and `kek_store…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-125","vendor":"Red Hat","product":"Linux","affected":["Linux >= b2715aa2e1352c0060b9dcba57a2e465bbfbcd68 < 81db79fed115640736188e56595b1e9aec317d5b","Linux >= b2715aa2e1352c0060b9dcba57a2e465bbfbcd68 < 4c6374dcb270d12907b880cf82a5a5ef21785fc3","Linux >= b2715aa2e1352c0060b9dcba57a2e465bbfbcd68 < 7cd8fe01aba303a2382db0966eb6c8ab41d5f3c2","Linux >= b2715aa2e1352c0060b9dcba57a2e465bbfbcd68 < 67b60703d7d8af1ca0e49f72e1bdb1ccecd41b5b","Linux >= b2715aa2e1352c0060b9dcba57a2e465bbfbcd68 < a7508c7959ff8d037327d377ed21a9c0eabe4674","Linux 6.6"],"published":"2026-09-11","updated":"2026-09-14","sourceUpdated":"2026-09-14T21:17:59+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81014.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81014.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-81014"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532503"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-81014"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81014"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-81014.mbox"},{"url":"https://git.kernel.org/stable/c/81db79fed115640736188e56595b1e9aec317d5b"},{"url":"https://git.kernel.org/stable/c/4c6374dcb270d12907b880cf82a5a5ef21785fc3"},{"url":"https://git.kernel.org/stable/c/7cd8fe01aba303a2382db0966eb6c8ab41d5f3c2"},{"url":"https://git.kernel.org/stable/c/67b60703d7d8af1ca0e49f72e1bdb1ccecd41b5b"},{"url":"https://git.kernel.org/stable/c/a7508c7959ff8d037327d377ed21a9c0eabe4674"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.00168,"epssPercentile":0.06451,"ingestedAt":"2026-09-14T15:23:07.454Z","slug":"CVE-2026-81014","body":"## Overview\n\nA flaw was found in the Linux kernel's `hp-bioscfg` module. A local attacker with write access to the `sysfs` entry for `hp-bioscfg` could exploit a heap out-of-bounds read vulnerability. This occurs because the `sk_store()` and `kek_store()` functions incorrectly handle input that ends with a newline character, causing a one-byte read beyond the allocated memory. This could lead to information disclosure.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81014.json)\n\n**kernel: platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store()** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-14.\n\nNot affected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nRefer to the advisory for fix availability.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":204132,"id":"CVE-2026-81014","ts":1789490231912,"field":"cvss","old":null,"new":"5.5"},{"seq":204131,"id":"CVE-2026-81014","ts":1789490231912,"field":"severity","old":"none","new":"medium"},{"seq":147105,"id":"CVE-2026-81014","ts":1789270195191,"field":"cvss","old":null,"new":"4.4"},{"seq":147104,"id":"CVE-2026-81014","ts":1789270195191,"field":"severity","old":"none","new":"medium"},{"seq":108860,"id":"CVE-2026-81014","ts":1789183729292,"field":"cvss","old":null,"new":"4.4"},{"seq":108859,"id":"CVE-2026-81014","ts":1789183729292,"field":"severity","old":"none","new":"medium"}]}