Out-of-bounds read in Linux kernel - CVE-2026-81013
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in validate_password_input() in the hp-bioscfg password attribute handling when writing an empty string to current_password or new_password. A local user can write an empty string to a password attribute to disclose sensitive information.