* [PATCH v5 1/9] platform/x86: hp-bioscfg: fix OOB reads in hp_get_string_from_buffer()
2026-10-07 13:47 [PATCH v5 0/9] platform/x86: hp-bioscfg: buffer handling fixes Muhammad Bilal
@ 2026-10-07 13:47 ` Muhammad Bilal
2026-10-07 13:47 ` [PATCH v5 2/9] platform/x86: hp-bioscfg: fix non-ASCII truncation " Muhammad Bilal
` (7 subsequent siblings)
8 siblings, 0 replies; 10+ messages in thread
From: Muhammad Bilal @ 2026-10-07 13:47 UTC (permalink / raw)
To: Jorge Lopez, Hans de Goede, Ilpo Järvinen
Cc: Andy Shevchenko, Thomas Weißschuh, platform-driver-x86,
linux-kernel, Muhammad Bilal, stable
The escape prescan loop uses 'size' as both its bound and its
accumulator, so each escape character found extends the loop and
reads past the end of src[].
Use the original u16 count as the loop bound. Also include the 2-byte
length prefix in the bounds check, pass the u16 count instead of the
byte count to utf16s_to_utf8s(), and advance the buffer by the bytes
actually consumed instead of the escape-inflated count.
Tested on HP EliteBook 840 G2 (Fedora 44, Linux 7.2.7).
Fixes: a34fc329b189 ("platform/x86: hp-bioscfg: bioscfg")
Cc: stable@vger.kernel.org
Suggested-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Muhammad Bilal <meatuni001@gmail.com>
---
Changes in v5:
drivers/platform/x86/hp/hp-bioscfg/bioscfg.c | 26 +++++++++++---------
1 file changed, 15 insertions(+), 11 deletions(-)
diff --git a/drivers/platform/x86/hp/hp-bioscfg/bioscfg.c b/drivers/platform/x86/hp/hp-bioscfg/bioscfg.c
index 32b99a862082..919735ddba25 100644
--- a/drivers/platform/x86/hp/hp-bioscfg/bioscfg.c
+++ b/drivers/platform/x86/hp/hp-bioscfg/bioscfg.c
@@ -58,8 +58,8 @@ int hp_get_integer_from_buffer(u8 **buffer, u32 *buffer_size, u32 *integer)
int hp_get_string_from_buffer(u8 **buffer, u32 *buffer_size, char *dst, u32 dst_size)
{
u16 *src = (u16 *)*buffer;
+ u16 orig_size;
u16 src_size;
-
u16 size;
int i;
int conv_dst_size;
@@ -67,17 +67,21 @@ int hp_get_string_from_buffer(u8 **buffer, u32 *buffer_size, char *dst, u32 dst_
if (*buffer_size < sizeof(u16))
return -EINVAL;
- src_size = *(src++);
- /* size value in u16 chars */
- size = src_size / sizeof(u16);
+ src_size = *src;
- /* Ensure there is enough space remaining to read and convert
- * the string
+ /*
+ * Ensure there is enough space remaining for the length prefix
+ * just read plus the string data it describes.
*/
- if (*buffer_size < src_size)
+ if (*buffer_size < sizeof(u16) + src_size)
return -EINVAL;
- for (i = 0; i < size; i++)
+ src++;
+ /* size value in u16 chars */
+ orig_size = src_size / sizeof(u16);
+ size = orig_size;
+
+ for (i = 0; i < orig_size; i++)
if (src[i] == '\\' ||
src[i] == '\r' ||
src[i] == '\n' ||
@@ -95,7 +99,7 @@ int hp_get_string_from_buffer(u8 **buffer, u32 *buffer_size, char *dst, u32 dst_
/*
* convert from UTF-16 unicode to ASCII
*/
- utf16s_to_utf8s(src, src_size, UTF16_HOST_ENDIAN, dst, conv_dst_size);
+ utf16s_to_utf8s(src, orig_size, UTF16_HOST_ENDIAN, dst, conv_dst_size);
dst[conv_dst_size] = 0;
for (i = 0; i < conv_dst_size; i++) {
@@ -121,8 +125,8 @@ int hp_get_string_from_buffer(u8 **buffer, u32 *buffer_size, char *dst, u32 dst_
src++;
}
- *buffer = (u8 *)src;
- *buffer_size -= size * sizeof(u16);
+ *buffer += sizeof(u16) + src_size;
+ *buffer_size -= sizeof(u16) + src_size;
return size;
}
--
2.55.0
^ permalink raw reply [flat|nested] 10+ messages in thread* [PATCH v5 2/9] platform/x86: hp-bioscfg: fix non-ASCII truncation in hp_get_string_from_buffer()
2026-10-07 13:47 [PATCH v5 0/9] platform/x86: hp-bioscfg: buffer handling fixes Muhammad Bilal
2026-10-07 13:47 ` [PATCH v5 1/9] platform/x86: hp-bioscfg: fix OOB reads in hp_get_string_from_buffer() Muhammad Bilal
@ 2026-10-07 13:47 ` Muhammad Bilal
2026-10-07 13:47 ` [PATCH v5 3/9] platform/x86: hp-bioscfg: return -E2BIG from validate_password_input() Muhammad Bilal
` (6 subsequent siblings)
8 siblings, 0 replies; 10+ messages in thread
From: Muhammad Bilal @ 2026-10-07 13:47 UTC (permalink / raw)
To: Jorge Lopez, Hans de Goede, Ilpo Järvinen
Cc: Andy Shevchenko, Thomas Weißschuh, platform-driver-x86,
linux-kernel, Muhammad Bilal, stable
utf16s_to_utf8s() writes into dst, but the loop that follows
overwrites dst from the raw UTF-16 code units with truncating casts,
so any character above U+007F is mangled. For example, U+00E9 is
stored as 0xe9 instead of 0xc3 0xa9.
Convert into a scratch buffer first, then escape '\\', '\r', '\n' and
'\t' into dst with string_escape_mem(). Quotes are not escaped, so the
existing strreplace() still handles them.
Tested on HP EliteBook 840 G2 (Fedora 44, Linux 7.2.7).
Fixes: a34fc329b189 ("platform/x86: hp-bioscfg: bioscfg")
Cc: stable@vger.kernel.org
Suggested-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Muhammad Bilal <meatuni001@gmail.com>
---
Changes in v3:
drivers/platform/x86/hp/hp-bioscfg/bioscfg.c | 62 +++++---------------
1 file changed, 14 insertions(+), 48 deletions(-)
diff --git a/drivers/platform/x86/hp/hp-bioscfg/bioscfg.c b/drivers/platform/x86/hp/hp-bioscfg/bioscfg.c
index 919735ddba25..754ab03bfd7b 100644
--- a/drivers/platform/x86/hp/hp-bioscfg/bioscfg.c
+++ b/drivers/platform/x86/hp/hp-bioscfg/bioscfg.c
@@ -11,7 +11,7 @@
#include <linux/module.h>
#include <linux/kernel.h>
#include <linux/printk.h>
-#include <linux/string.h>
+#include <linux/string_helpers.h>
#include <linux/wmi.h>
#include "bioscfg.h"
#include "../../firmware_attributes_class.h"
@@ -57,12 +57,12 @@ int hp_get_integer_from_buffer(u8 **buffer, u32 *buffer_size, u32 *integer)
int hp_get_string_from_buffer(u8 **buffer, u32 *buffer_size, char *dst, u32 dst_size)
{
+ char utf8_buf[MAX_BUFF_SIZE];
u16 *src = (u16 *)*buffer;
+ int escaped_len;
u16 orig_size;
u16 src_size;
- u16 size;
- int i;
- int conv_dst_size;
+ int utf8_len;
if (*buffer_size < sizeof(u16))
return -EINVAL;
@@ -79,56 +79,22 @@ int hp_get_string_from_buffer(u8 **buffer, u32 *buffer_size, char *dst, u32 dst_
src++;
/* size value in u16 chars */
orig_size = src_size / sizeof(u16);
- size = orig_size;
-
- for (i = 0; i < orig_size; i++)
- if (src[i] == '\\' ||
- src[i] == '\r' ||
- src[i] == '\n' ||
- src[i] == '\t')
- size++;
- /*
- * Conversion is limited to destination string max number of
- * bytes.
- */
- conv_dst_size = size;
- if (size >= dst_size)
- conv_dst_size = dst_size - 1;
+ utf8_len = utf16s_to_utf8s(src, orig_size, UTF16_HOST_ENDIAN,
+ utf8_buf, sizeof(utf8_buf));
- /*
- * convert from UTF-16 unicode to ASCII
- */
- utf16s_to_utf8s(src, orig_size, UTF16_HOST_ENDIAN, dst, conv_dst_size);
- dst[conv_dst_size] = 0;
-
- for (i = 0; i < conv_dst_size; i++) {
- if (*src == '\\' ||
- *src == '\r' ||
- *src == '\n' ||
- *src == '\t') {
- dst[i++] = '\\';
- if (i == conv_dst_size)
- break;
- }
-
- if (*src == '\r')
- dst[i] = 'r';
- else if (*src == '\n')
- dst[i] = 'n';
- else if (*src == '\t')
- dst[i] = 't';
- else if (*src == '"')
- dst[i] = '\'';
- else
- dst[i] = *src;
- src++;
- }
+ escaped_len = string_escape_mem(utf8_buf, utf8_len, dst, dst_size - 1,
+ ESCAPE_SPACE | ESCAPE_SPECIAL,
+ "\\\r\n\t");
+ if (escaped_len > dst_size - 1)
+ escaped_len = dst_size - 1;
+ dst[escaped_len] = '\0';
+ strreplace(dst, '"', '\'');
*buffer += sizeof(u16) + src_size;
*buffer_size -= sizeof(u16) + src_size;
- return size;
+ return escaped_len;
}
int hp_get_common_data_from_buffer(u8 **buffer_ptr, u32 *buffer_size,
--
2.55.0
^ permalink raw reply [flat|nested] 10+ messages in thread* [PATCH v5 3/9] platform/x86: hp-bioscfg: return -E2BIG from validate_password_input()
2026-10-07 13:47 [PATCH v5 0/9] platform/x86: hp-bioscfg: buffer handling fixes Muhammad Bilal
2026-10-07 13:47 ` [PATCH v5 1/9] platform/x86: hp-bioscfg: fix OOB reads in hp_get_string_from_buffer() Muhammad Bilal
2026-10-07 13:47 ` [PATCH v5 2/9] platform/x86: hp-bioscfg: fix non-ASCII truncation " Muhammad Bilal
@ 2026-10-07 13:47 ` Muhammad Bilal
2026-10-07 13:47 ` [PATCH v5 4/9] platform/x86: hp-bioscfg: allow clearing current_password Muhammad Bilal
` (5 subsequent siblings)
8 siblings, 0 replies; 10+ messages in thread
From: Muhammad Bilal @ 2026-10-07 13:47 UTC (permalink / raw)
To: Jorge Lopez, Hans de Goede, Ilpo Järvinen
Cc: Andy Shevchenko, Thomas Weißschuh, platform-driver-x86,
linux-kernel, Muhammad Bilal, stable
validate_password_input() returns the positive INVALID_BIOS_AUTH on
rejection. store_password_instance() skips the store on nonzero ret,
but its final "return ret < 0 ? ret : count" treats the positive value
as success, so userspace sees count instead of an error.
Return -E2BIG for an invalid password length.
Tested on HP EliteBook 840 G2 (Fedora 44, Linux 7.2.7): writing 999
bytes to current_password returned 999 before this change.
Fixes: 8646a3b5ee3a ("platform/x86: hp-bioscfg: passwdobj-attributes")
Cc: stable@vger.kernel.org
Signed-off-by: Muhammad Bilal <meatuni001@gmail.com>
---
Changes in v3:
drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c | 7 ++++---
1 file changed, 4 insertions(+), 3 deletions(-)
diff --git a/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c b/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c
index 9b989ef756ea..8018ccb2b439 100644
--- a/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c
+++ b/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c
@@ -70,12 +70,13 @@ static int validate_password_input(int instance_id, const char *buf)
length--;
if (length > MAX_PASSWD_SIZE)
- return INVALID_BIOS_AUTH;
+ return -E2BIG;
if (password_data->min_password_length > length ||
password_data->max_password_length < length)
- return INVALID_BIOS_AUTH;
- return SUCCESS;
+ return -E2BIG;
+
+ return 0;
}
ATTRIBUTE_N_PROPERTY_SHOW(is_enabled, password);
--
2.55.0
^ permalink raw reply [flat|nested] 10+ messages in thread* [PATCH v5 4/9] platform/x86: hp-bioscfg: allow clearing current_password
2026-10-07 13:47 [PATCH v5 0/9] platform/x86: hp-bioscfg: buffer handling fixes Muhammad Bilal
` (2 preceding siblings ...)
2026-10-07 13:47 ` [PATCH v5 3/9] platform/x86: hp-bioscfg: return -E2BIG from validate_password_input() Muhammad Bilal
@ 2026-10-07 13:47 ` Muhammad Bilal
2026-10-07 13:47 ` [PATCH v5 5/9] platform/x86: hp-bioscfg: fix off-by-one in password length check Muhammad Bilal
` (4 subsequent siblings)
8 siblings, 0 replies; 10+ messages in thread
From: Muhammad Bilal @ 2026-10-07 13:47 UTC (permalink / raw)
To: Jorge Lopez, Hans de Goede, Ilpo Järvinen
Cc: Andy Shevchenko, Thomas Weißschuh, platform-driver-x86,
linux-kernel, Muhammad Bilal, stable
The ABI documents echo "" > current_password as the way to end a
session, but validate_password_input() rejects an empty string when
min_password_length is nonzero, so the password stays cached.
Skip the length check for an empty current_password so the write
clears it.
Compile tested only.
Fixes: 8646a3b5ee3a ("platform/x86: hp-bioscfg: passwdobj-attributes")
Cc: stable@vger.kernel.org
Signed-off-by: Muhammad Bilal <meatuni001@gmail.com>
---
Changes in v5:
.../platform/x86/hp/hp-bioscfg/passwdobj-attributes.c | 9 +++++++--
1 file changed, 7 insertions(+), 2 deletions(-)
diff --git a/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c b/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c
index 8018ccb2b439..96172342d4a0 100644
--- a/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c
+++ b/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c
@@ -60,7 +60,8 @@ int hp_get_password_instance_for_type(const char *name)
return -EINVAL;
}
-static int validate_password_input(int instance_id, const char *buf)
+static int validate_password_input(int instance_id, const char *buf,
+ bool is_current)
{
int length;
struct password_data *password_data = &bioscfg_drv.password_data[instance_id];
@@ -69,6 +70,10 @@ static int validate_password_input(int instance_id, const char *buf)
if (length > 0 && buf[length - 1] == '\n')
length--;
+ /* An empty current_password clears the session password */
+ if (is_current && !length)
+ return 0;
+
if (length > MAX_PASSWD_SIZE)
return -E2BIG;
@@ -97,7 +102,7 @@ static int store_password_instance(struct kobject *kobj, const char *buf,
id = get_password_instance_id(kobj);
if (id >= 0)
- ret = validate_password_input(id, buf_cp);
+ ret = validate_password_input(id, buf_cp, is_current);
}
if (!ret) {
--
2.55.0
^ permalink raw reply [flat|nested] 10+ messages in thread* [PATCH v5 5/9] platform/x86: hp-bioscfg: fix off-by-one in password length check
2026-10-07 13:47 [PATCH v5 0/9] platform/x86: hp-bioscfg: buffer handling fixes Muhammad Bilal
` (3 preceding siblings ...)
2026-10-07 13:47 ` [PATCH v5 4/9] platform/x86: hp-bioscfg: allow clearing current_password Muhammad Bilal
@ 2026-10-07 13:47 ` Muhammad Bilal
2026-10-07 13:47 ` [PATCH v5 6/9] platform/x86: hp-bioscfg: fix heap OOB in hp_enforce_single_line_input() Muhammad Bilal
` (3 subsequent siblings)
8 siblings, 0 replies; 10+ messages in thread
From: Muhammad Bilal @ 2026-10-07 13:47 UTC (permalink / raw)
To: Jorge Lopez, Hans de Goede, Ilpo Järvinen
Cc: Andy Shevchenko, Thomas Weißschuh, platform-driver-x86,
linux-kernel, Muhammad Bilal
current_password and new_password hold MAX_PASSWD_SIZE bytes including
the NUL, but validate_password_input() accepts a password of exactly
MAX_PASSWD_SIZE characters when the firmware limits allow it.
strscpy() then truncates it and fails with -E2BIG, which
store_password_instance() ignores, so the write reports success with a
truncated password stored.
For example, with a max_password_length of 64 or more, writing 64
characters succeeds but only 63 are stored.
Reject lengths of MAX_PASSWD_SIZE or more.
Compile tested only.
Fixes: 8646a3b5ee3a ("platform/x86: hp-bioscfg: passwdobj-attributes")
Signed-off-by: Muhammad Bilal <meatuni001@gmail.com>
---
Changes in v4:
drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c b/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c
index 96172342d4a0..af2635e31c0b 100644
--- a/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c
+++ b/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c
@@ -74,7 +74,7 @@ static int validate_password_input(int instance_id, const char *buf,
if (is_current && !length)
return 0;
- if (length > MAX_PASSWD_SIZE)
+ if (length >= MAX_PASSWD_SIZE)
return -E2BIG;
if (password_data->min_password_length > length ||
--
2.55.0
^ permalink raw reply [flat|nested] 10+ messages in thread* [PATCH v5 6/9] platform/x86: hp-bioscfg: fix heap OOB in hp_enforce_single_line_input()
2026-10-07 13:47 [PATCH v5 0/9] platform/x86: hp-bioscfg: buffer handling fixes Muhammad Bilal
` (4 preceding siblings ...)
2026-10-07 13:47 ` [PATCH v5 5/9] platform/x86: hp-bioscfg: fix off-by-one in password length check Muhammad Bilal
@ 2026-10-07 13:47 ` Muhammad Bilal
2026-10-07 13:47 ` [PATCH v5 7/9] platform/x86: hp-bioscfg: validate SPM state returned by firmware Muhammad Bilal
` (2 subsequent siblings)
8 siblings, 0 replies; 10+ messages in thread
From: Muhammad Bilal @ 2026-10-07 13:47 UTC (permalink / raw)
To: Jorge Lopez, Hans de Goede, Ilpo Järvinen
Cc: Andy Shevchenko, Thomas Weißschuh, platform-driver-x86,
linux-kernel, Muhammad Bilal, stable
The store handlers copy the input with kstrdup(), which stops at the
first NUL, but pass the full write size to
hp_enforce_single_line_input(). With an embedded NUL the copy is
shorter than count, so the helper reads, and can write one byte, past
the allocation.
Writing "A\0" followed by 4093 bytes of "B" to current_password makes
memchr() scan 4093 bytes past a 2-byte copy. On an HP EliteBook 840 G2
running Linux 7.2.7 all 100 such writes fail with -EINVAL although the
input has no newline, so memchr() matched one in the heap. A userspace
replica of the helper under ASan reports a 4095 byte read, 0 bytes
after the 2-byte region, and is clean with this change.
The input is a string, so only scan up to its first NUL.
Fixes: a34fc329b189 ("platform/x86: hp-bioscfg: bioscfg")
Cc: stable@vger.kernel.org
Suggested-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Muhammad Bilal <meatuni001@gmail.com>
---
Changes in v5:
drivers/platform/x86/hp/hp-bioscfg/bioscfg.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/platform/x86/hp/hp-bioscfg/bioscfg.c b/drivers/platform/x86/hp/hp-bioscfg/bioscfg.c
index 754ab03bfd7b..84d75926d768 100644
--- a/drivers/platform/x86/hp/hp-bioscfg/bioscfg.c
+++ b/drivers/platform/x86/hp/hp-bioscfg/bioscfg.c
@@ -166,6 +166,8 @@ int hp_enforce_single_line_input(char *buf, size_t count)
{
char *p;
+ /* buf is a string, ignore anything after its first NUL */
+ count = strnlen(buf, count);
p = memchr(buf, '\n', count);
if (p == buf + count - 1)
--
2.55.0
^ permalink raw reply [flat|nested] 10+ messages in thread* [PATCH v5 7/9] platform/x86: hp-bioscfg: validate SPM state returned by firmware
2026-10-07 13:47 [PATCH v5 0/9] platform/x86: hp-bioscfg: buffer handling fixes Muhammad Bilal
` (5 preceding siblings ...)
2026-10-07 13:47 ` [PATCH v5 6/9] platform/x86: hp-bioscfg: fix heap OOB in hp_enforce_single_line_input() Muhammad Bilal
@ 2026-10-07 13:47 ` Muhammad Bilal
2026-10-07 13:47 ` [PATCH v5 8/9] platform/x86: hp-bioscfg: NUL-terminate the SPM auth token Muhammad Bilal
2026-10-07 13:47 ` [PATCH v5 9/9] platform/x86: hp-bioscfg: fix oops on short integer attribute buffer Muhammad Bilal
8 siblings, 0 replies; 10+ messages in thread
From: Muhammad Bilal @ 2026-10-07 13:47 UTC (permalink / raw)
To: Jorge Lopez, Hans de Goede, Ilpo Järvinen
Cc: Andy Shevchenko, Thomas Weißschuh, platform-driver-x86,
linux-kernel, Muhammad Bilal, stable
status_show() indexes the 3-entry spm_state_types[] with the state byte
returned by firmware. update_spm_state() stores the same byte, which
key_mechanism_show() uses to index the 3-entry spm_mechanism_types[].
Neither is range checked, so a state above 2 makes the world-readable
status and key_mechanism files print a string from a pointer read past
the array.
Return -EIO for an out of range state.
Compile tested only.
Fixes: b2715aa2e135 ("platform/x86: hp-bioscfg: spmobj-attributes")
Cc: stable@vger.kernel.org
Signed-off-by: Muhammad Bilal <meatuni001@gmail.com>
---
Changes in v5:
drivers/platform/x86/hp/hp-bioscfg/spmobj-attributes.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/drivers/platform/x86/hp/hp-bioscfg/spmobj-attributes.c b/drivers/platform/x86/hp/hp-bioscfg/spmobj-attributes.c
index 2d4a3720f80c..25477ecf8822 100644
--- a/drivers/platform/x86/hp/hp-bioscfg/spmobj-attributes.c
+++ b/drivers/platform/x86/hp/hp-bioscfg/spmobj-attributes.c
@@ -6,6 +6,7 @@
* Copyright (c) 2022 HP Development Company, L.P.
*/
+#include <linux/array_size.h>
#include "bioscfg.h"
static const char * const spm_state_types[] = {
@@ -118,6 +119,9 @@ static ssize_t update_spm_state(void)
if (ret < 0)
return ret;
+ if (data.state >= ARRAY_SIZE(spm_mechanism_types))
+ return -EIO;
+
bioscfg_drv.spm_data.mechanism = data.state;
if (bioscfg_drv.spm_data.mechanism)
bioscfg_drv.spm_data.is_enabled = 1;
@@ -153,6 +157,9 @@ static ssize_t status_show(struct kobject *kobj, struct kobj_attribute
if (ret < 0)
return ret;
+ if (data.state >= ARRAY_SIZE(spm_state_types))
+ return -EIO;
+
/*
* 'status' is a read-only file that returns ASCII text in
* JSON format reporting the status information.
--
2.55.0
^ permalink raw reply [flat|nested] 10+ messages in thread* [PATCH v5 8/9] platform/x86: hp-bioscfg: NUL-terminate the SPM auth token
2026-10-07 13:47 [PATCH v5 0/9] platform/x86: hp-bioscfg: buffer handling fixes Muhammad Bilal
` (6 preceding siblings ...)
2026-10-07 13:47 ` [PATCH v5 7/9] platform/x86: hp-bioscfg: validate SPM state returned by firmware Muhammad Bilal
@ 2026-10-07 13:47 ` Muhammad Bilal
2026-10-07 13:47 ` [PATCH v5 9/9] platform/x86: hp-bioscfg: fix oops on short integer attribute buffer Muhammad Bilal
8 siblings, 0 replies; 10+ messages in thread
From: Muhammad Bilal @ 2026-10-07 13:47 UTC (permalink / raw)
To: Jorge Lopez, Hans de Goede, Ilpo Järvinen
Cc: Andy Shevchenko, Thomas Weißschuh, platform-driver-x86,
linux-kernel, Muhammad Bilal, stable
auth_token_store() copies the token with kmemdup(), which does not NUL
terminate it, but hp_calculate_security_buffer() and
hp_populate_security_buffer() use it as a C string and read past the
allocation.
A lone newline (echo > auth_token) is worse: kmemdup() of 0 bytes
returns ZERO_SIZE_PTR, which passes the NULL checks, so a later
attribute write passes it to strlen().
A userspace replica of the two helpers under ASan reports a heap
buffer overflow in hp_calculate_security_buffer() for the unterminated
token and a fault at address 0x10 for the lone newline, and is clean
with this change.
The token is a string, so copy it with kstrndup(), which always NUL
terminates and allocates at least one byte.
Fixes: b2715aa2e135 ("platform/x86: hp-bioscfg: spmobj-attributes")
Cc: stable@vger.kernel.org
Signed-off-by: Muhammad Bilal <meatuni001@gmail.com>
---
Changes in v5:
drivers/platform/x86/hp/hp-bioscfg/spmobj-attributes.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/platform/x86/hp/hp-bioscfg/spmobj-attributes.c b/drivers/platform/x86/hp/hp-bioscfg/spmobj-attributes.c
index 25477ecf8822..598bf3e1260e 100644
--- a/drivers/platform/x86/hp/hp-bioscfg/spmobj-attributes.c
+++ b/drivers/platform/x86/hp/hp-bioscfg/spmobj-attributes.c
@@ -317,7 +317,7 @@ static ssize_t auth_token_store(struct kobject *kobj,
length--;
/* allocate space and copy current auth token */
- bioscfg_drv.spm_data.auth_token = kmemdup(buf, length, GFP_KERNEL);
+ bioscfg_drv.spm_data.auth_token = kstrndup(buf, length, GFP_KERNEL);
if (!bioscfg_drv.spm_data.auth_token) {
ret = -ENOMEM;
goto exit_token;
--
2.55.0
^ permalink raw reply [flat|nested] 10+ messages in thread* [PATCH v5 9/9] platform/x86: hp-bioscfg: fix oops on short integer attribute buffer
2026-10-07 13:47 [PATCH v5 0/9] platform/x86: hp-bioscfg: buffer handling fixes Muhammad Bilal
` (7 preceding siblings ...)
2026-10-07 13:47 ` [PATCH v5 8/9] platform/x86: hp-bioscfg: NUL-terminate the SPM auth token Muhammad Bilal
@ 2026-10-07 13:47 ` Muhammad Bilal
8 siblings, 0 replies; 10+ messages in thread
From: Muhammad Bilal @ 2026-10-07 13:47 UTC (permalink / raw)
To: Jorge Lopez, Hans de Goede, Ilpo Järvinen
Cc: Andy Shevchenko, Thomas Weißschuh, platform-driver-x86,
linux-kernel, Muhammad Bilal, stable
hp_populate_integer_elements_from_buffer() ignores the return value of
hp_get_string_from_buffer(). When fewer than 2 bytes are left in the
buffer, dst_size is 0, kcalloc() returns ZERO_SIZE_PTR and
hp_get_string_from_buffer() fails without writing to it, so
kstrtoint() faults on address 0x10.
Return the error instead.
Compile tested only.
Fixes: 6f2c06d5a467 ("platform/x86: hp-bioscfg: int-attributes")
Cc: stable@vger.kernel.org
Signed-off-by: Muhammad Bilal <meatuni001@gmail.com>
---
Changes in v4:
drivers/platform/x86/hp/hp-bioscfg/int-attributes.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/drivers/platform/x86/hp/hp-bioscfg/int-attributes.c b/drivers/platform/x86/hp/hp-bioscfg/int-attributes.c
index 5373af71549a..41287e08c7bb 100644
--- a/drivers/platform/x86/hp/hp-bioscfg/int-attributes.c
+++ b/drivers/platform/x86/hp/hp-bioscfg/int-attributes.c
@@ -329,7 +329,12 @@ static int hp_populate_integer_elements_from_buffer(u8 *buffer_ptr, u32 *buffer_
// VALUE:
integer_data->current_value = 0;
- hp_get_string_from_buffer(&buffer_ptr, buffer_size, dst, dst_size);
+ ret = hp_get_string_from_buffer(&buffer_ptr, buffer_size, dst, dst_size);
+ if (ret < 0) {
+ kfree(dst);
+ return ret;
+ }
+
ret = kstrtoint(dst, 10, &integer_data->current_value);
if (ret)
pr_warn("Unable to convert string to integer: %s\n", dst);
--
2.55.0
^ permalink raw reply [flat|nested] 10+ messages in thread