Off-by-one in Linux kernel - CVE-2026-81012
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to perform an out-of-bounds write.
The vulnerability exists due to an off-by-one error in hp_get_string_from_buffer() in the hp-bioscfg driver when converting a string whose length equals the destination buffer size. A local user can cause the function to process such a string to perform an out-of-bounds write.