PT-2026-6132 · Linux+2 · Linux Kernel+2

Published

2026-01-01

·

Updated

2026-05-22

·

CVE-2026-23062

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains an issue within the hp bioscfg driver related to the GET INSTANCE ID macro. This macro could lead to a kernel panic when accessing sysfs attributes. The issue stems from two primary causes: an off-by-one error in a loop condition (using '<=' instead of '<'), resulting in out-of-bounds array access, and a missing NULL check before dereferencing attr name kobj->name, causing a null pointer dereference in functions like min length show(). The panic was observed when the fwupd utility attempted to read BIOS configuration attributes. The vulnerable code is located within the min length show() function.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2026-23062
OPENSUSE-SU-2026:20416-1
SUSE-SU-2026:0962-1
SUSE-SU-2026:1081-1
SUSE-SU-2026:20838-1
SUSE-SU-2026:20931-1
SUSE-SU-2026:21284-1
USN-8278-1
USN-8289-1
USN-8296-1

Affected Products

Linux Kernel
Ubuntu
Fwupd