{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store()  sk_store() and kek_store() strip a trailing newline from the sysfs write before allocating the key buffer:  \tlength = count; \tif (buf[length - 1] == '\\n') \t\tlength--; \tbioscfg_drv.spm_data.signing_key = kmemdup(buf, length, GFP_KERNEL);  but then pass the original \"count\" (not \"length\") as the copy size to hp_wmi_perform_query(), which memcpy()s that many bytes out of the \"length\"-sized allocation, reading one byte past it whenever the write ends in a newline, the normal case for a shell \"echo\" into sysfs.  KASAN confirms this directly:    BUG: KASAN: slab-out-of-bounds in hp_wmi_perform_query+0x1e9/0x460 [hp_bioscfg]   Read of size 28 at addr ffff88813c8e2b80 by task python3/16022   ...   sk_store+0xa7/0x240 [hp_bioscfg]   kernfs_fop_write_iter+0x3e1/0x5d0   ...   The buggy address is located 0 bytes inside of   allocated 27-byte region [ffff88813c8e2b80, ffff88813c8e2b9b)  Reproduced identically for kek_store, and at multiple write sizes (28, 57, 201 bytes), each time reading exactly one byte past a kmemdup() allocation one byte smaller than the write.  Fix by passing \"length\" instead of \"count\" to hp_wmi_perform_query() in both functions.",
  "id": "DEBIAN-CVE-2026-81014",
  "modified": "2026-09-15T08:47:32.600326510Z",
  "published": "2026-09-11T20:19:10.297Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-81014"
    }
  ],
  "upstream": [
    "CVE-2026-81014"
  ]
}