From nobody Fri Oct 2 08:25:16 2026 Received: from mail-wm1-f42.google.com (mail-wm1-f42.google.com [209.85.128.42]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7DA3E3126C0 for ; Mon, 3 Aug 2026 14:30:54 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.42 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785767457; cv=none; b=nv5TaKLGE11UQw4VvxMUBKKEBrPxwcPzE+RKD4GA+l9R26Vd/mK0pgYgYRylSDfsJY+Hfs9OB6qENrUjLwhBK2aW72vPit2GGxc4aLURQbmqlNcCSitXK1njXBzzVuVQn2uHy2uB6KuYniRDmHaxqTVMtq5cR4QCyeL2C6oOEkU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785767457; c=relaxed/simple; bh=OA1LKTN49b5FUMf9V/yVYL0uyXf1T9fnPQ99xO6TDc4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=J35zECd+pDVSL5bId9ESPR8HpOLHnOlxByrVjnEgvOJmxHOTXAh/qUnirGzzAA/Buy8NnnbxQQEA5r3KHChSWnMQemI9Sxnr6Hyr2sS2fL2n9NWXIwKqeNZ8Q3LWM70nrps2Rurc3mEOhZ8dqbnIbB1pt+Z7NoP3wFM/5jsp31U= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=j5U5yhws; arc=none smtp.client-ip=209.85.128.42 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="j5U5yhws" Received: by mail-wm1-f42.google.com with SMTP id 5b1f17b1804b1-4957eefd361so14966165e9.1 for ; Mon, 03 Aug 2026 07:30:53 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785767452; x=1786372252; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=9gdrr7AdAYBlVDbcFRIgxo33EdXDmWd6yiBKqM/w3XU=; b=j5U5yhwsTyH+U4iVWzHP8r5NInK1VVUwZW1yOXBWcT/bJGPZbJ428AEpdRbAWPRake ZFtN2WPAwhCQs7wpo3uVAQdmAxfA8kdaZTXVniLGgqjt+z9cURPQuEUJgUv5kZMpmbFi u7ppiqqdvSJdP7OTyDDbc1+pFgxKItGFHXCpRuBBb7DoTFrSGhg70pvQ5mV4s+9Dc0sC SFCUf5F8R44nhU5Flznl3ESnEVtsvQng9hk09yNSaEYBBNSXZqHXAF4HA/wgyBL52IP8 JJ4HkwwxpcOu28y2VR1SfMpO1WBALv0YVAw2Ad0DhUgV5E+tGH2jVALM1RZTt174SsKn flUw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785767452; x=1786372252; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=9gdrr7AdAYBlVDbcFRIgxo33EdXDmWd6yiBKqM/w3XU=; b=JiMYemhEGu36DLMn8iMW/ZjGdgmHet1t29h7//iaHXVrYlcASfnIiwhB+MnWukdkZh D1X0R38p+MG66e1o9HOm6milz8oxtDz8ZEZSSCmM26idQyI8Zzo3miHTsPzqP1ekO3Qc MclA+4yoaT6lCatIjB+OmR5PHmb9TfTrx+qZxtFCRftqMZNm+cgQ5vd42VjfkiWLIQeW oxLuy9akCeXUmWpXxeQk5mLykCxUDG/9F1k1mZpkfXWM4IUK4vHpr6SSt8TDajksTXg8 Z6lMOZB5cKAJlFKo4gB3elh6CwcS85/TTd2lTUYg5hd2ACBLJdNdWMfjSh+0VAxpYLWu RKzA== X-Forwarded-Encrypted: i=1; AHgh+RoAdfC2KiE3ramjIoBpjhKsyf08PuEOwoqZQF/iYlw7VkDiUHFn9W44MXFoSH4SDDwvcWT8dZUEzETSawo=@vger.kernel.org X-Gm-Message-State: AOJu0YyromT/cI571qVPGixONdt/H6DzVYQsP60fZuEDXs16bRDNDle3 WaMA6FRBVv7KWu7lkQ+2OqCOq6/yOpLnogNT3QdikJ1gyrAgNeOYT94/ X-Gm-Gg: AR+sD12SEBHFbs8wPwI0ijnNCBAQweerPaD/LW08DONnLF7cq5xuedCcCiyc1MENb8J CH2FJC/hBKZ17EfRmSjLYk1c2AeE3CvfHGRSYUsR0c5adoVTOK3qIMVndNFdiKzP7/aYnVla27H MjqB/ojZ81rDV0m9p2a/uPL2M6KJdvJB3nRQQQJGDxO1ZKyckFogO0ChU1VP1HwDgDbpLBR24Ri +5HVBuF15bP7+rJ75qxwINmt9qyXDIrW+8YL1qZNHzxeMKi9D7rBsD7bVhRhaqE2EGaFbrvU4f1 SWPkGTzbEr7oyRb8COeVmvkSGyFVTm7RVG7zAGEoMRK1Ibdt6MfiF9LFlp6+qgLarx9ZVjCmvlp 6k92UaEgcLSfSyO5l+R3leoJ8o04/0R0DCKDUgJyDlqYT5JBlFdMXEzVRiBnGmxSLnn3HjMbUm9 QbSeJryU2/wkkLTOpTKq5/oqHc+YfKfu2/ld8DC1XtWlJJ4dBi/x5hlbOEObqMq0frR0Ziec2CY LhGyytQAn0qRXYiA2TJJ2EqkyjqgHUh9SOSEcMQ7w== X-Received: by 2002:a05:600d:8492:b0:496:c2fd:1731 with SMTP id 5b1f17b1804b1-4980c64b96dmr166980395e9.1.1785767451905; Mon, 03 Aug 2026 07:30:51 -0700 (PDT) Received: from fedora ([202.47.63.86]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49807b98284sm236575295e9.12.2026.08.03.07.30.49 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 03 Aug 2026 07:30:51 -0700 (PDT) From: Muhammad Bilal To: platform-driver-x86@vger.kernel.org Cc: jorge.lopez2@hp.com, hansg@kernel.org, ilpo.jarvinen@linux.intel.com, linux@weissschuh.net, linux-kernel@vger.kernel.org, meatuni001@gmail.com, stable@vger.kernel.org Subject: [PATCH 01/13] platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer Date: Mon, 3 Aug 2026 19:30:24 +0500 Message-ID: <20260803143037.93105-2-meatuni001@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260803143037.93105-1-meatuni001@gmail.com> References: <20260803143037.93105-1-meatuni001@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" hp_get_string_from_buffer() clamps the converted string length against the destination buffer size with "size > dst_size", so when the converted length is exactly equal to dst_size, conv_dst_size is left at dst_size and the unconditional NUL terminator write dst[conv_dst_size] =3D 0; lands one byte past the destination buffer. This is the same shape of bug as the previously fixed off-by-one in hp_convert_hexstr_to_str(): the buffer is sized correctly for the content, but the terminator write is never checked against that size. Fix by changing the comparison to ">=3D" so conv_dst_size is always left with room for the terminator. All fixed-size destinations that reach this function (path[512], current_value[512], current_password/current_value[64], and the per-entry buffers in encodings[][512] and prerequisites[][512]) are affected. Fixes: a34fc329b189 ("platform/x86: hp-bioscfg: bioscfg") Cc: stable@vger.kernel.org Signed-off-by: Muhammad Bilal --- drivers/platform/x86/hp/hp-bioscfg/bioscfg.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/platform/x86/hp/hp-bioscfg/bioscfg.c b/drivers/platfor= m/x86/hp/hp-bioscfg/bioscfg.c index 2bf57e6eade4..0edc6e7cfa9a 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/bioscfg.c +++ b/drivers/platform/x86/hp/hp-bioscfg/bioscfg.c @@ -85,7 +85,7 @@ int hp_get_string_from_buffer(u8 **buffer, u32 *buffer_si= ze, char *dst, u32 dst_ * bytes. */ conv_dst_size =3D size; - if (size > dst_size) + if (size >=3D dst_size) conv_dst_size =3D dst_size - 1; =20 /* --=20 2.55.0 From nobody Fri Oct 2 08:25:16 2026 Received: from mail-wm1-f52.google.com (mail-wm1-f52.google.com [209.85.128.52]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 885E3378D74 for ; Mon, 3 Aug 2026 14:30:58 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.52 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785767461; cv=none; b=s4rkGhhXtRTXK8hxny3C8dJcPUsbbyjTyOM56xxoiIThHSX481ioUdBmOivzvMTHHErbd08tJVbVyfMhLNBk2uCMGUU/L4TQ3c69W/EP6coYkk19qKhQvjNArJeGdZ1ZBHiKocUOQrOovuOCR0MnIdVTx5ygRGtfDaQkeJ14F1Y= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785767461; c=relaxed/simple; bh=GXnVaGcOYcGeGF51vfhkksxSxm5iT6MduRJD27H8KxI=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=fiOzrXqnNhgsVR8QMLNJnr3YiinlE7wOShNLTuWTkTU2Ep8fKN7kxd5mpcTjf2ecv1mjkHGYBI3z9Fgq21ATsrlrik7hcA/kGx3NdG8gx6xAJBpAVnILSSDl8q1Eo3r4Pb6FsLlOKAt0nmBm/mJmNf7X3v0IfAwX7WscJRn/O08= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=cMgunFXV; arc=none smtp.client-ip=209.85.128.52 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="cMgunFXV" Received: by mail-wm1-f52.google.com with SMTP id 5b1f17b1804b1-4980dc26022so13781915e9.1 for ; Mon, 03 Aug 2026 07:30:58 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785767455; x=1786372255; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=jRznYyon0XGUdVgbipyEvsqHsHiyM4eqeCRczfbwZQQ=; b=cMgunFXVWhAQ0qA/a8BWNqAE4aMvnXbCv+t2appMzu75LJ6iLzHYzH4FrpXyv6xGvu 3lyZWCK1VE0nU6bVgCsWufB5ElqeEzSEU4s3ZO2gFDWkAPNYfMh/eldeTQO40U3Nv1By ut0WeWBmoWOeod3dBUQWsbu9AGV9Smfe1GZfsdu/3jXYzk+cDRzO2pJEKNs4tD+MIcFL zxL4ZOoX+1ZYpsMXJhwaR3c6xhVJ3Z/nFgotwoQLlkAh1v/t2yoFn7auBmbDDWaagifI 6nywVuzr4zB4QNzezEq7c12+c8H/OBPYEfyposjxzs70p1xySaFcKffkBnGqoANG/LnG /Xdw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785767455; x=1786372255; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=jRznYyon0XGUdVgbipyEvsqHsHiyM4eqeCRczfbwZQQ=; b=dcaPPpc2jiHfI6mwe9AM37LTpZ6pjFYAB+sxJa8SYKosjrkOCH9wTGv6pTfGu3kcDn KIcE28ZyzfYXPnBc4MkJsBe+Jo3Nlguue3vXuM2cX18wZ0D6/GE2cGXGvMyN+kKhnbyk NYNWJTKfQI/gjb6IYM7NKMow5phFg+MF72xfU9xWnLQ1vVlVmDBjjQ/PPBaEt2Xdg7+8 Y1f8j2QV1JnZCl58zO1R1mfSLNj7okEGF+iXCg3W4uim13lz3OFka5Ew61UyNQDTdLUz L/hhHY8lBJef9Z8HKitqx0leWFgTItT/ewX/oBM1L/EEwpt0JlXDPoJ5zOqd6j3K7KdK yjXQ== X-Forwarded-Encrypted: i=1; AHgh+RpiA+6BhwofbkBv8ig07XX6/wPm/f/K+HGBKncTriOlNG6T+t1FyLn9qTc6vZByHQU19YAgWOgXG2OP9c0=@vger.kernel.org X-Gm-Message-State: AOJu0Yz0DPfTe747RWYHxUgM3E+Z3/stmyXllmmBJpd+zQ5pHLYVnEqt AllU/xIIvwhZHTVXefL0MUCVAFhfRwVKUv8zXeP152rnA01gS1i5feWm X-Gm-Gg: AR+sD11LqpkQf1gtlew9ECPkPAJu1Snl7x+wBiLcnRdz2RJNk/J1Uwm/QfrV1ogKgsx i1Z4m6unlInnFW8+eKnZtTkHKCUywV87VEgj7Bmmny+u5DlBlyEJvm3rgMuXtsITmjittKQQF6j Bio8JKyrFvztnE3smRZY7Tpuds/nxfKsz9xnucEgIjA2UCVecm+lpSDlIZDK4CrGCEZk5Cj5Toy Yhb7FK50M0Gis7HOi55HKLGWXiAGBzcCcDsLo+ZIMtuGz3SHyfpaivoVFFGrAvsiMBIxcFggNSd MJef6xI+DB7/8Ed3NWIdm6XU91TnWGx1yh1HkKRSsPN+l3Q0yhtNH/jjLrs552sZ+PxqMhg/5Kl LC+v0BNZwvhC2pLmikSShplj5PaYxVIM1eXeSrnVvJD0lTLCbBwMOQQcj9mPXoWd3mwJC/YnSmS dD6SFRpWQrDzmwLHPmu1DAeqOmREowCcBXJUoeNbQscZf8dzjNWH6TfcxeB6TPNIY2YXvve0Tmm TWKGTD7fqvKJNCQYsanksCNFaYuFx6EdpYc7g1WdQ== X-Received: by 2002:a05:600c:840f:b0:493:b6ee:fcb7 with SMTP id 5b1f17b1804b1-4980c6507e7mr211322355e9.14.1785767454564; Mon, 03 Aug 2026 07:30:54 -0700 (PDT) Received: from fedora ([202.47.63.86]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49807b98284sm236575295e9.12.2026.08.03.07.30.52 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 03 Aug 2026 07:30:54 -0700 (PDT) From: Muhammad Bilal To: platform-driver-x86@vger.kernel.org Cc: jorge.lopez2@hp.com, hansg@kernel.org, ilpo.jarvinen@linux.intel.com, linux@weissschuh.net, linux-kernel@vger.kernel.org, meatuni001@gmail.com, stable@vger.kernel.org Subject: [PATCH 02/13] platform/x86: hp-bioscfg: fix heap OOB read in sk_store and kek_store Date: Mon, 3 Aug 2026 19:30:25 +0500 Message-ID: <20260803143037.93105-3-meatuni001@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260803143037.93105-1-meatuni001@gmail.com> References: <20260803143037.93105-1-meatuni001@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" sk_store() and kek_store() strip a trailing newline from the sysfs write before allocating the key buffer: length =3D count; if (buf[length - 1] =3D=3D '\n') length--; bioscfg_drv.spm_data.signing_key =3D kmemdup(buf, length, GFP_KERNEL); but then pass the original "count" (not "length") as the copy size to hp_wmi_perform_query(), which memcpy()s that many bytes out of the "length"-sized allocation, reading one byte past it whenever the write ends in a newline, the normal case for a shell "echo" into sysfs. KASAN confirms this directly: BUG: KASAN: slab-out-of-bounds in hp_wmi_perform_query+0x1e9/0x460 [hp_bi= oscfg] Read of size 28 at addr ffff88813c8e2b80 by task python3/16022 ... sk_store+0xa7/0x240 [hp_bioscfg] kernfs_fop_write_iter+0x3e1/0x5d0 ... The buggy address is located 0 bytes inside of allocated 27-byte region [ffff88813c8e2b80, ffff88813c8e2b9b) Reproduced identically for kek_store, and at multiple write sizes (28, 57, 201 bytes), each time reading exactly one byte past a kmemdup() allocation one byte smaller than the write. Fix by passing "length" instead of "count" to hp_wmi_perform_query() in both functions. Fixes: b2715aa2e135 ("platform/x86: hp-bioscfg: spmobj-attributes") Cc: stable@vger.kernel.org Signed-off-by: Muhammad Bilal --- drivers/platform/x86/hp/hp-bioscfg/spmobj-attributes.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/drivers/platform/x86/hp/hp-bioscfg/spmobj-attributes.c b/drive= rs/platform/x86/hp/hp-bioscfg/spmobj-attributes.c index 2b00a14792e9..4d94e48c1a4c 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/spmobj-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/spmobj-attributes.c @@ -238,7 +238,7 @@ static ssize_t sk_store(struct kobject *kobj, ret =3D hp_wmi_perform_query(HPWMI_SECUREPLATFORM_SET_SK, HPWMI_SECUREPLATFORM, (void *)bioscfg_drv.spm_data.signing_key, - count, 0); + length, 0); =20 if (!ret) { bioscfg_drv.spm_data.mechanism =3D SIGNING_KEY; @@ -274,7 +274,7 @@ static ssize_t kek_store(struct kobject *kobj, ret =3D hp_wmi_perform_query(HPWMI_SECUREPLATFORM_SET_KEK, HPWMI_SECUREPLATFORM, (void *)bioscfg_drv.spm_data.endorsement_key, - count, 0); + length, 0); =20 if (!ret) { bioscfg_drv.spm_data.mechanism =3D ENDORSEMENT_KEY; --=20 2.55.0 From nobody Fri Oct 2 08:25:16 2026 Received: from mail-wm1-f44.google.com (mail-wm1-f44.google.com [209.85.128.44]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4BD303D7A01 for ; Mon, 3 Aug 2026 14:31:00 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.44 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785767464; cv=none; b=DC4ya4dqYraHncojBztS2MIOUTkPKjEpKyVp3i2GwylFPQkXPhgcd2JQkvpBf9lBbIlla7E+KfNKmlWkIgkWpYsNpx1j8KjwMZBPpeqxvH68VKraN12a1dgH3WD+XW/EtzBdFxzon4S8ckJ3H61apWgdc0pSLDD5KXKP//8IV9c= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785767464; c=relaxed/simple; bh=r6Cbjl4OVGNVNoYln0kbEziovWGUtHxY0z02La/a0yE=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=DDumYLFoYghgdkHxoKDshfeu9Nks0jPiPY9JaQKe3BRc98DeVl9W2VTK/QWpUboXKkwVvlRj/UgMVifxJxTKi6/n7QNWdXMYYJrQ4wu2Cumatn1EGABrGjKNavCjZQNFqJEN+gjnH+xOBK84eE/7B890O/AAxHGU0S/W+EuofH8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=QWayDztU; arc=none smtp.client-ip=209.85.128.44 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="QWayDztU" Received: by mail-wm1-f44.google.com with SMTP id 5b1f17b1804b1-4955aa106b1so20050585e9.0 for ; Mon, 03 Aug 2026 07:31:00 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785767458; x=1786372258; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=PdRDhdZcnRfVrf9wRzs0djvfPZrw61+L7S7NLduJJu4=; b=QWayDztU8it3Z5kTxP2qIecS6McYqBN5ZIAauyqoelfQPiwQ5IgtzqJWwFtCa/aPkU tqeS3AyD80t3lz60mJqFqOBLMSO9VPNUgnpvcfQGIgatmokTPf0pHJG179hbmDZELOjC NGXaFqKU5surkpjguKyxyXSgiYiX/AGK2Zpn7lSmBdogkgCliHxRwmTOTaGeGlL85IoN zrm+H5rVta6yvf9JmqzQkugYhvFg2m65cDkbkIH92x6TJ/4sQie7XNqqLxbIy9lMD5YR Y5oPq7F77fOtxQqw1oA4Hkfp4Gyxw3boiDAe3Sz5vzCNieDadPPtrc2Kd3C5bMm+PBq4 0L/g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785767458; x=1786372258; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=PdRDhdZcnRfVrf9wRzs0djvfPZrw61+L7S7NLduJJu4=; b=H4fc0dNhZBl47yT/0lgNtnJZeNJJc4fmv9VJSuC4ESAtK1+c6k3O2jCafgbDqDemlR M414xb8QzAyPv603EX/8Dv6cKaCvsnk0+RwA4TY1F3eh4O3cqykOcuAc3Q00POf51/Wy s3xjln5ZFkQ2CZCmS/Y3K2M+4JIvOEghN4WKFbzFS6np/N6LVQ4bC0qsJAXyr8EB0o3g 8IYu/DTCOkcUa4bU2fJS+FOrF2AjWhsT/1gmcwcOvdg0nWx9oLGYn2Bfl10hRH/8VKDv 5q9HfGYdHST0TdYbRU4yk4nLeLc/4WwNXVuY+v7973iKGk649IRv3CzSMnXq9e14hGKS iOpw== X-Forwarded-Encrypted: i=1; AHgh+RoySOYu8s+KJvBvkX0AL4TJO+apvxXIIrCJEhuVMY2b3TmnkuHFNOI/I/JPKh4sdHffXFQKGaYrkVT5nqk=@vger.kernel.org X-Gm-Message-State: AOJu0Yw5yWAKk8xMjgWPVrOqFxabzbvtwQu0BrH1mNtDJx0eDnuQRlEI J3E0UM/3Lb4JRJp4Re9kSSQNsFUErY/H7hmMPsmwQJEzxrAIlidLd5UZ X-Gm-Gg: AR+sD106F2ZMWEZQrQkDr6aAjeI6tWTZMeE/LvK09G3xX3psetKHyDYbWJDiFe3AYY+ sYbnKFVHw+olsJfW4iBCAs/c9dV8qAnJwgX3Ra6f0LdtePf5/ADuAdPnpPnjQVZ3De3pxRwx1Lp S8hTK8Hso7y07guAFNqLsUpxMZ7GQuWbn5CTtn+F8pE8nEjE7kVgXFBp9Oxwb3dt7U4ZVbRwPEL rELOzsostyzf6MwlYqeKZ7LpIkHwoqBpQONc1kuAJ7/uq7aPYFKDtGclX9R2rHta0a5QsIyMqIv 4gBmZBxwZczSWSopWnhgb4/AZaXKuZC8YypP333GRA2H9rH3+KLyUhIGpXOYuJSZrgsMYoAVVwm J2+c+xOw0LOpLb50k4uF2drhWMyQFNMnsIjvcV27XavvpedU7f+toJK5u5wXVeDJZw9vtfH3h7i 4uZLT/U3tfVekdgCSV1ngXFzDMDYJTSi1TQIxA60+qtItY3163dYlQFZ3XG2D+zoCLirre8B2h7 6cxwhobtPCrI1iCcuKcBp6wq/diIz2miVRscyE2Qg== X-Received: by 2002:a05:600d:8489:10b0:495:69eb:27fe with SMTP id 5b1f17b1804b1-4980c674ef9mr180887235e9.11.1785767457599; Mon, 03 Aug 2026 07:30:57 -0700 (PDT) Received: from fedora ([202.47.63.86]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49807b98284sm236575295e9.12.2026.08.03.07.30.54 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 03 Aug 2026 07:30:57 -0700 (PDT) From: Muhammad Bilal To: platform-driver-x86@vger.kernel.org Cc: jorge.lopez2@hp.com, hansg@kernel.org, ilpo.jarvinen@linux.intel.com, linux@weissschuh.net, linux-kernel@vger.kernel.org, meatuni001@gmail.com, stable@vger.kernel.org Subject: [PATCH 03/13] platform/x86: hp-bioscfg: fix heap OOB read on empty password write Date: Mon, 3 Aug 2026 19:30:26 +0500 Message-ID: <20260803143037.93105-4-meatuni001@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260803143037.93105-1-meatuni001@gmail.com> References: <20260803143037.93105-1-meatuni001@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" validate_password_input() computes length =3D strlen(buf) and then checks buf[length - 1] to strip a trailing newline, without checking that length is nonzero first. Writing an empty string (a bare '\n') to current_password or new_password gives length =3D=3D 0, and buf[length - 1] reads buf[-1], one byte before the heap allocation holding the copied input. KASAN confirms this directly: BUG: KASAN: slab-out-of-bounds in store_password_instance.constprop.0+0x2= 23/0x2a0 [hp_bioscfg] Read of size 1 at addr ffff88811bd8da9f by task sh/13740 ... store_password_instance.constprop.0+0x223/0x2a0 [hp_bioscfg] current_password_store+0x14/0x20 [hp_bioscfg] ... The buggy address is located 23 bytes to the right of allocated 8-byte region [ffff88811bd8da80, ffff88811bd8da88) Reproduced identically via new_password_store. Execution continues past the bad read (the garbage byte only affects whether "length" is decremented by one), so the write completes and returns success; this is a pure information read past the buffer, not a crash, but it is still an out-of-bounds access KASAN correctly flags. Fix by only checking buf[length - 1] when length is nonzero. Fixes: 8646a3b5ee3a ("platform/x86: hp-bioscfg: passwdobj-attributes") Cc: stable@vger.kernel.org Signed-off-by: Muhammad Bilal --- drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c b/dr= ivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c index 4d79eb8056a5..86fa03a5ee9a 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c @@ -66,7 +66,7 @@ static int validate_password_input(int instance_id, const= char *buf) struct password_data *password_data =3D &bioscfg_drv.password_data[instan= ce_id]; =20 length =3D strlen(buf); - if (buf[length - 1] =3D=3D '\n') + if (length > 0 && buf[length - 1] =3D=3D '\n') length--; =20 if (length > MAX_PASSWD_SIZE) --=20 2.55.0 From nobody Fri Oct 2 08:25:16 2026 Received: from mail-wm1-f50.google.com (mail-wm1-f50.google.com [209.85.128.50]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A0EC6411FA8 for ; Mon, 3 Aug 2026 14:31:02 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.50 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785767466; cv=none; b=blbKc6yT3JlMqIPYpXJiUUmeEYTYLNT4znRBRNtvfJvN7aDurKzkOHS5U0lfi0vj9UT60ccbL/10QYU4KYO1snMSTnRTe4ye9EOa8ecub2ZxxBBXH6VqrdzCcYU5+tb/YO6SHWdxmuDM3cnFgmJKfmVw1N8YDb9FCXotSeVZN/8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785767466; c=relaxed/simple; bh=ATKvWl1DnIWOGmblRvXvDZPEp2qoEl7qqfbdLw7wl3E=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=QDRQndg2QvDmmqvKdlhT7jaw0EWqeem4PZpU1zbFG3RWDPxuN4NbKbOwTCGGkGmQHledWuB31+vRse44CKPvtqeSGCGch3yH0omoB1idqKy60ocgEGucGd6r3A7xl965H8EA67/V0CToy5J/WD6nop8udQvUUssd4YejCDDMNps= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=q/kKcjoQ; arc=none smtp.client-ip=209.85.128.50 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="q/kKcjoQ" Received: by mail-wm1-f50.google.com with SMTP id 5b1f17b1804b1-4955de8797cso13013835e9.3 for ; Mon, 03 Aug 2026 07:31:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785767460; x=1786372260; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=GsPuPtlEtpcGKckM/9mBE7kyPjRyXeXRo57w8zpUvug=; b=q/kKcjoQurIZJba6iduZ88NlhqYGrmWV436lC2J0r0OgfmhlU7HLHy/ChZnQzH0E+0 qbxbaWsVedKx0nfbGxpenB1MLHF2P07CU1sowJP/YxrDtrZ71bDRX+naeA7h7EFExxkL x3955u55v7nCzXii+GD4Q+ItEoYZnUxeO0lDGv7uPxWhIP6SZN8aRMu1dTN59dd1BN8N 5pQuOvoyH7wNcCitaOdcwejW+KZcWUFlxUKqHh2DCMwVTcU363/RytNbOgPHRyS+QO1i buofXTMeGWKRokWQgOv2mMgp6Kt69XtiwdOch7CwZM284irOTQBB7wq7sRaYLj0AlnyI tdpw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785767460; x=1786372260; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=GsPuPtlEtpcGKckM/9mBE7kyPjRyXeXRo57w8zpUvug=; b=Zliis8tej9pgMmcSDCikAbt0o12wJQW2FTcjM72RN8tgXSyRfTecbF2SeKEHXvMrfc mCQTBG4APU75ce4q7rVHCpBUzbhWVHUVO+AII+gBa+xOprn6GaQEEtKHKw+k5omV2DHZ XiWJU0mS+381eTuVe50fEb0oQvW2sH7gekhwp66Dw3aEKNlA0t02md7iK50M9XU8kRg/ l5ey+AY8kWd5IVSk9JNZKAV8mmEiH3KO291TQ2tVOEEsmZX6LmDtGGo/CaG4CiQEdtsX EFvA0Bw3VqOI13+GPW1VfT3wO55uO/2+2emkT4NCrbhGsMh3JF3EsAt45pzpXwWXRipP UXZw== X-Forwarded-Encrypted: i=1; AHgh+Rqi7RAX0SnlipT3a/5bNSPOveyxWWQNz/68lKB7i713DAtW9SQWfqmlXUsouA8L902jMmGwayXhKFlvhXg=@vger.kernel.org X-Gm-Message-State: AOJu0YwIqXnWkt5utjBz1vm/wOQM87fw0r9KnD6HCNwKGegSi9c9yuXc ElR/SysqeB376R8raxrHcjhbxfIItRXZjhpN0iCLS2UULQV+UolmHaWq X-Gm-Gg: AR+sD10XMIeckfLIGRFEiWcHWk7r5pgUTEQ7OvE7LUTJNP/FoiFf46b5IA3HtHTLr18 EKoN7HU53UrvqMd7RX7SIJm+QTrHz6pkk81QdfBIwT+15pHIq7iFt4qJqAPMZhvPve0e8N/cQ5P +mmqLjRIcwsdcpZL1xPl4m61pSqF4Y4047qRMZmRnFzallWCybD/0XWwPVwFV0q9qJDhAPsDBI/ vq8LS3wxPX9vK3pBxx5Db0xsHYeGjv9rCmDRj5lNzs5bIg1gbKdgq2/vfxuaNmpd3BMq8wR17pt GtmfEdUDJFpaXcqBh7oFXM5L8Ck6s5DhHhV34tYGeHMRhHt3ql533Zug2TKVmnsaQ9/CCJ1Vu4B ZKISZAM/I4NV1aCstFPnJV3ftjXk3LTN9SdV9FMxkKGkE30BzK7xEg7jJqfTV8gZ+qYQIO4A4tP fWFK5XDYObzKUcLQA5JmrfgsQL+1h+sUeicypQDM1cCCIZFg2hCggy8aQTnqXQyH1/UqCvA7Nef hTJKUup9MpmAuoMYyvpPKZsIICO7lUUZ2aRmCBolQ== X-Received: by 2002:a05:600c:840f:b0:495:5fdf:2075 with SMTP id 5b1f17b1804b1-4980c5fa29amr206226845e9.0.1785767460389; Mon, 03 Aug 2026 07:31:00 -0700 (PDT) Received: from fedora ([202.47.63.86]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49807b98284sm236575295e9.12.2026.08.03.07.30.57 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 03 Aug 2026 07:31:00 -0700 (PDT) From: Muhammad Bilal To: platform-driver-x86@vger.kernel.org Cc: jorge.lopez2@hp.com, hansg@kernel.org, ilpo.jarvinen@linux.intel.com, linux@weissschuh.net, linux-kernel@vger.kernel.org, meatuni001@gmail.com, stable@vger.kernel.org Subject: [PATCH 04/13] platform/x86: hp-bioscfg: fix 16-byte heap overflow for empty auth token Date: Mon, 3 Aug 2026 19:30:27 +0500 Message-ID: <20260803143037.93105-5-meatuni001@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260803143037.93105-1-meatuni001@gmail.com> References: <20260803143037.93105-1-meatuni001@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" hp_calculate_security_buffer() special-cases an empty authentication string and returns a fixed 4 bytes (sizeof(u16) * 2). But hp_populate_security_buffer() does not special-case that same input: for any authentication string that does not start with BEAM_PREFIX, including the empty string, it always builds "UTF_PREFIX + authentication" and converts the result to UTF-16, writing a 2-byte length header plus 2 bytes per character of "" (9 characters), 20 bytes total, regardless of how long "authentication" itself is. The caller, hp_set_attribute(), sizes its kmalloc() buffer using hp_calculate_security_buffer()'s return value, so for an empty authentication token it allocates 4 bytes for the security area but hp_populate_security_buffer() then writes 20 bytes into it, a 16-byte heap buffer overflow. The authentication token used here is the current admin/setup password, which is an empty string by default until one is configured. Any write to a writable BIOS attribute while no admin password has been set reaches this path. Fix by removing the special-case short return for an empty string in hp_calculate_security_buffer() and letting the normal formula run, which already accounts for the UTF_PREFIX correctly for the non-empty case; for an empty string this naturally yields the same 20 bytes that hp_populate_security_buffer() writes. Fixes: b2715aa2e135 ("platform/x86: hp-bioscfg: spmobj-attributes") Cc: stable@vger.kernel.org Signed-off-by: Muhammad Bilal --- drivers/platform/x86/hp/hp-bioscfg/spmobj-attributes.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/platform/x86/hp/hp-bioscfg/spmobj-attributes.c b/drive= rs/platform/x86/hp/hp-bioscfg/spmobj-attributes.c index 4d94e48c1a4c..2d4a3720f80c 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/spmobj-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/spmobj-attributes.c @@ -48,7 +48,7 @@ size_t hp_calculate_security_buffer(const char *authentic= ation) =20 authlen =3D strlen(authentication); if (!authlen) - return sizeof(u16) * 2; + return sizeof(u16) + strlen(UTF_PREFIX) * sizeof(u16); =20 size =3D sizeof(u16) + authlen * sizeof(u16); if (!strstarts(authentication, BEAM_PREFIX)) --=20 2.55.0 From nobody Fri Oct 2 08:25:16 2026 Received: from mail-wr1-f45.google.com (mail-wr1-f45.google.com [209.85.221.45]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 43037412BF8 for ; Mon, 3 Aug 2026 14:31:05 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.45 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785767469; cv=none; b=Las6ZEXCK532dSXrOY2iq5JeiBTunSk81dZEmvOQkStpSAXP99iLaePIjhvS67TAXCLqqviUoKbwuNh//BOQwFUGvV4aq/aoMwkWgy6CoPQ0CzouBCvXWkMekdmRzTr0ojGC/Bzj+5HI0zOKR2WrGKEEY4SL97RWCtU6EJihXyM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785767469; c=relaxed/simple; bh=9EehTMGdJoM/pmPAG9mZtREZbrypCyCVR7Mvq/DwalQ=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=RVXKbVOvWMNdqP2gDIXN+4K78RDNydt1fXMu/mm+iTiWjiotoKac+2Sa2r4gunIcXKcXYdW5XCAvLmV4BprZ4ui8wS3qP6JAGVtpzyY5y15RiRgQqRYsiggBls7TyVuIvmM/sYDgjoN7DdbXmV3r2G0lf2nSXa7Z//yHTVhwomY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=Kn4k6TWc; arc=none smtp.client-ip=209.85.221.45 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="Kn4k6TWc" Received: by mail-wr1-f45.google.com with SMTP id ffacd0b85a97d-47f64ca1c2dso1006643f8f.2 for ; Mon, 03 Aug 2026 07:31:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785767464; x=1786372264; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=K+s/eo+/pWpLLFnoufPaOpVfgTjc+a46l3h08Co/MXY=; b=Kn4k6TWcQ7JqkozjWnJ65K7r0vJ3xuxicjgv4NL77v4z0s0+VpsKwj86jGriBrXlBC j6Xsu5PwruWz8XStm82TLY528+iK1V9P+1LBQ6/fHebJQHCyBEQY55JYsM4oBs3nqhl2 HQBiOPaFuzXyaTbyajGSPuFh3j4y1G0z01kpQq+6cQK+ssZrmgY1btEWbyyJ7SfLdWck wINc3bVOYlBzU+xErlNu3b4UcRzafDPuFcc8mpZdJ/krXbMDdNa7GV/ss2TXn8uv0pSh vksaSPwDL3GJ8YVxmbeoXV5zF+UNw6iXSaW86c0yNguZTG7Q+K+CfFLzwpqakp2d0UG9 v3Vg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785767464; x=1786372264; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=K+s/eo+/pWpLLFnoufPaOpVfgTjc+a46l3h08Co/MXY=; b=gDkX+jQREfkqgb0/96bfJbtoyi8VSFrLrWOaOIglO/jqf7yEF+x96sXDzXWmJ2U5xG N2qRLr3l5meEk7r8d6mgONk97ii/Izq+yRHIRLXA6Zb6oG2M24/EhELfRZOvmZQMvdnm X38r5MfJRnewSpDehShjoWsRseWWrP3ZiEiYAevQxVd5ddv2Y460tjfCw80kSW1AXqju UxwupuJD6aMVvkAsR9OpYCnkC+UYUewGSO7/Vtdq/pMlWLRqyXZgpEzC40weY6aVeVPl SbzYlJOR8cNJ+1avHddFaGjZ8zN/XHZKcIz2efzPsDEzO+R+X6g+QhxdZgm3mEtA/ffJ /dxA== X-Forwarded-Encrypted: i=1; AHgh+RpYhakxeldtQJw8jqfI9s2BfJYmqGTACAopkc/eLyoQsLuLpQ/a9ao6GyLt/6R9ddEWi4DfF8qB0XR3PQA=@vger.kernel.org X-Gm-Message-State: AOJu0YzywisRgbJRCDEJ50ZqnQh9VVsiaz9iRvxkr+jZvUZJAVuWNQ7O DGo44uEFGX5vZQH2yW7x68pXYwlTmv/8fY2mTaM51aZMe9vnGGeLDbA2 X-Gm-Gg: AR+sD13Y8ZGgbMCIIJo8Ue3EEPik8FF1bdQKOvaeUvo+HZpv3FoXzhAXoEHt1+mwNqc DDoZWZsRyGn7CitbIenlXRNYiTCx3BkvuZ5uLQtcP8Dsh9juUGpLjn+SsajuNaS2znJl8l2kWlx hiUEDhz4IUXGDjXMqog55Pi59l6zFMvQA4pVfmR70Br8197snS8Uktoqc5GKwLDMbb1mLFEjhgK 5lVHcriMk68hRQ7yZjVLqrFobkt2+9gj5k/SIZrD6q1jIKLZynOqfgpi8Io5mkcY413iRfKG4mF SwGBRZbhEYRFiq458avsNvy3oYC7CMs36Mjtej6gwlpSJe7us1edNiWzEYt2VVG63E67wylSFiB tM9cG5RaLALg7ktMnnKkOEMYXh6qy0kqzSUIZt/vWY8Nad3QnlrLhgnADCmtEJwP2zS/b6fZdFx QPmLxIlIgR8R8fa5rrP6Ospwkqc78LwGpibu8drE7gYZ1jAE4hCFQBDNndV4ZyPnEcVeAJQh/1+ RdUbDyoZzdWefn+mzE9VVs63E3Z1jJk+oNCmlQ7R4E= X-Received: by 2002:a05:600c:5395:b0:493:faf3:3ea5 with SMTP id 5b1f17b1804b1-4980c66c751mr293605105e9.4.1785767463425; Mon, 03 Aug 2026 07:31:03 -0700 (PDT) Received: from fedora ([202.47.63.86]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49807b98284sm236575295e9.12.2026.08.03.07.31.00 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 03 Aug 2026 07:31:02 -0700 (PDT) From: Muhammad Bilal To: platform-driver-x86@vger.kernel.org Cc: jorge.lopez2@hp.com, hansg@kernel.org, ilpo.jarvinen@linux.intel.com, linux@weissschuh.net, linux-kernel@vger.kernel.org, meatuni001@gmail.com, stable@vger.kernel.org Subject: [PATCH 05/13] platform/x86: hp-bioscfg: fix off-by-one heap OOB write in audit_log_entries_show Date: Mon, 3 Aug 2026 19:30:28 +0500 Message-ID: <20260803143037.93105-6-meatuni001@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260803143037.93105-1-meatuni001@gmail.com> References: <20260803143037.93105-1-meatuni001@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The per-iteration guard in audit_log_entries_show() is: if (ret < 0 || (LOG_ENTRY_SIZE * i) > PAGE_SIZE) break; ... memcpy(buf, audit_log_buffer, LOG_ENTRY_SIZE); buf +=3D LOG_ENTRY_SIZE; At i =3D=3D 256 (PAGE_SIZE / LOG_ENTRY_SIZE), LOG_ENTRY_SIZE * i equals PAGE_SIZE exactly, which is not ">" PAGE_SIZE, so the loop does not break and instead writes another LOG_ENTRY_SIZE (16) bytes starting at offset 4096 of the page-sized sysfs output buffer, one entry past its end. This needs the BIOS to report more than 256 audit log entries, which already exceeds this driver's own documented LOG_MAX_ENTRIES of 254, so it requires a non-compliant or corrupted firmware value rather than the roughly 85 million entries an unrelated integer-overflow read of this code might suggest. Fix by checking the bound against the offset the write is about to reach, (i + 1), instead of the offset already written. Fixes: 63e8f906e94e ("platform/x86: hp-bioscfg: surestart-attributes") Cc: stable@vger.kernel.org Signed-off-by: Muhammad Bilal --- drivers/platform/x86/hp/hp-bioscfg/surestart-attributes.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/platform/x86/hp/hp-bioscfg/surestart-attributes.c b/dr= ivers/platform/x86/hp/hp-bioscfg/surestart-attributes.c index b57e42f29282..6b63fdb84606 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/surestart-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/surestart-attributes.c @@ -90,7 +90,7 @@ static ssize_t audit_log_entries_show(struct kobject *kob= j, HPWMI_SURESTART, audit_log_buffer, 1, 128); =20 - if (ret < 0 || (LOG_ENTRY_SIZE * i) > PAGE_SIZE) { + if (ret < 0 || (LOG_ENTRY_SIZE * (i + 1)) > PAGE_SIZE) { /* * Encountered a failure while reading * individual logs. Only a partial list of --=20 2.55.0 From nobody Fri Oct 2 08:25:16 2026 Received: from mail-wm1-f45.google.com (mail-wm1-f45.google.com [209.85.128.45]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 86D6E40DFBD for ; Mon, 3 Aug 2026 14:31:08 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.45 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785767470; cv=none; b=BltGkJoih2DVyZvbU/6IxfUj8z9cZF1zDiNBunIRVTs1oS4mMUjs2jrPieiMuumdS85n9OliyV5mEtzi9E8AdYGG9V6IKpJhBqOTtXH/vGv39MFg5aUMu/kDCWecF4VXrf/xRUmVcNvMyPZld7BTMBIBNKSHumnIGEveqHBJp3Y= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785767470; c=relaxed/simple; bh=rhV+qOT/cedymAeQ3DQaL+LQcUHG8piPrtIkVunzAvs=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=V19TagNBNBorUcv2AZuWHuVR+Wr8brjyu2e92pN1WtfTXq1nvZMEMJBmUWpGWewiwPj9Rnt6ROTi6x+Bx0qTQsR09yCliA9Y3EDRjiGSi5wayQigCycdhZAuKjYYyfmikp5R6tK4cY0n2lKhObmQ6hzOcVXyMZda1uI6MRC/8pA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=ocRj+FK3; arc=none smtp.client-ip=209.85.128.45 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="ocRj+FK3" Received: by mail-wm1-f45.google.com with SMTP id 5b1f17b1804b1-4980dc26022so13784345e9.1 for ; Mon, 03 Aug 2026 07:31:08 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785767466; x=1786372266; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=hNoDrCXm49lLgm2lL6InxDz3MAxyPtaZVFbbdYtrWx4=; b=ocRj+FK3AEnX5Nld63RlI6N4AAoJhPXAfs9T8hZzjcSB4Pg+8YvHdN3TlCqC81jakX t3K6esULZ6+xtHsvrj8pVijO08HSBDe4bypRRFAFw3zH9BP2uVR7suvdkbpEHEujmt+n fwYGlNrpwG0UMHd6rUSAW1VnIWXYHVO4/GM8S+xGtQKvDJ56VPTRB1jyQuDZFZoJf3DO 5AoOoFZAndWSDH5bpGeAkGKeF2jYHUGRYOXcWISc3eD9I58uTTiKXBa28cfENLd1HWkU OJ4nUmC4zrqNDaNdWQ4GX6f7nkRcgkhJrnyWUnMoyHht+0dMhcN9uj5PuRJdAH91LZCK 0h1Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785767466; x=1786372266; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=hNoDrCXm49lLgm2lL6InxDz3MAxyPtaZVFbbdYtrWx4=; b=JGYQ/iCreUSc3xmJBUg4NEeLCw1b4jnzMzKD5OZQM1VVHVWUXIxxR4dBejxIxOWMWn W2G5WX6r2GIsT8fRr4lLKdULl13yW5mQhc/hBB3NrHDjUKvoRcdADR9gWq0qpqRHIPvK /AP8Vf5LfXP7Q7djStpGpFJiDvvrjEjsPjIhDER84GiWL6nKpfsuzJ6sRLdq1J6w0+yb SEj6H64UJItWfwrPwz2kxSmOjl4PVQ/cK+Cc90ynooX3FrAoLg1Df3p5R2exXp+F1IOu PhJON0XFeyztrn7QDbt92NKkJU7Mj16zeo1Wn/CEOOduAyOMPY4hcp7Itfo3D9jDbtlJ kc3A== X-Forwarded-Encrypted: i=1; AHgh+RrSVgNf5YwG4C0zLhDU68a5oiWv2m77rTQZSpEEiZV98sJ6MPVsKpTQf3tLq87jdBRx5EM5LlLKL0iAn4I=@vger.kernel.org X-Gm-Message-State: AOJu0Yw2soJYx6oxQJSUPU+9wyZlXG8dUqRFyfPKIWXQ46P1OwkTuJbD TL/ewnbZe3U487TyZd3FpsRi4kLA3hdanOpWL9EkikDTk+4w5R2dAzaAD81OpEniZmY= X-Gm-Gg: AR+sD106qJiD3GHsKemMC8zpZxNPHsm/OgcYpGlh98pCJCUhenHrsOyV7kDc+4SFOxS fQZKeUMOvAAG7uvjwoNK8sbaQVSB9ikTFDSMGHu4u0JhYwJYtyLyFj7s3FWKtGK1MTtmAJHtzG1 lP6WcB7IgBYTx9yTgi92LmhsOvZz27YbD51NXGuy0FLIxzlzvnCbVLUsOYUwK9UJWKcz558zehA 6ruM/SnDDGuJq6A3QF5TbIO7JUkFdBxwZgLqDYcqy1U5uQb0LrwhX6xuBNd3kxBmrbKlQzLroE6 LI4TcXLVHb2C71YD64L4oaKuv5zaauVCdAnrpQreerRzeFqrCOytBy7Sm79WkaYlBhZUnVDV2pW UsJ8u03IPXFxxJQaxn48t5tHwzm1R3UCQ4rDk2bJrZIkXcGIrKzi9GoVWtj64YVjUbYdhLTEBTm M3xJ8rTi7DGZtejFJviFgUQH02nT+oj85Vqh+zXm5ix9DJoJ59V5lTvi2u2ykxVR6Y4YKZ8/VTx mJorVbrc6sMsjlGiLjTRZrsF6M1Cg+B01C6CWwfhA== X-Received: by 2002:a05:600d:8443:20b0:493:e974:41ac with SMTP id 5b1f17b1804b1-4980c6562c5mr183910265e9.16.1785767466371; Mon, 03 Aug 2026 07:31:06 -0700 (PDT) Received: from fedora ([202.47.63.86]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49807b98284sm236575295e9.12.2026.08.03.07.31.03 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 03 Aug 2026 07:31:05 -0700 (PDT) From: Muhammad Bilal To: platform-driver-x86@vger.kernel.org Cc: jorge.lopez2@hp.com, hansg@kernel.org, ilpo.jarvinen@linux.intel.com, linux@weissschuh.net, linux-kernel@vger.kernel.org, meatuni001@gmail.com, stable@vger.kernel.org Subject: [PATCH 06/13] platform/x86: hp-bioscfg: add missing bounds check in PSWD_ENCODINGS loop Date: Mon, 3 Aug 2026 19:30:29 +0500 Message-ID: <20260803143037.93105-7-meatuni001@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260803143037.93105-1-meatuni001@gmail.com> References: <20260803143037.93105-1-meatuni001@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The PREREQUISITES loop earlier in the same function checks "elem + reqs" against password_obj_count before indexing the ACPI package element array: if (elem + reqs >=3D password_obj_count) { pr_err("Error elem-objects package is too small\n"); return -EINVAL; } The PSWD_ENCODINGS loop performs the identical indexing pattern, password_obj[elem + pos_values], with no equivalent check, causing an out-of-bounds read of the package element array whenever encodings_size is larger than the number of elements actually present. Fix by adding the same bounds check, matching PREREQUISITES. Fixes: 8646a3b5ee3a ("platform/x86: hp-bioscfg: passwdobj-attributes") Cc: stable@vger.kernel.org Signed-off-by: Muhammad Bilal --- drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c b/dr= ivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c index 86fa03a5ee9a..acb123985ede 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c @@ -351,6 +351,11 @@ static int hp_populate_password_elements_from_package(= union acpi_object *passwor case PSWD_ENCODINGS: size =3D min_t(u32, password_data->encodings_size, MAX_ENCODINGS_SIZE); for (pos_values =3D 0; pos_values < size; pos_values++) { + if (elem + pos_values >=3D password_obj_count) { + pr_err("Error elem-objects package is too small\n"); + return -EINVAL; + } + ret =3D hp_convert_hexstr_to_str(password_obj[elem + pos_values].strin= g.pointer, password_obj[elem + pos_values].string.length, &str_value, &value_len); --=20 2.55.0 From nobody Fri Oct 2 08:25:16 2026 Received: from mail-wm1-f42.google.com (mail-wm1-f42.google.com [209.85.128.42]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6B07930FF30 for ; Mon, 3 Aug 2026 14:31:11 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.42 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785767473; cv=none; b=cPhaoBsRizrT2KaTDF+zKqFYMPGm/XKFrfd+0YXq3TS9ytiDolFGni33McH/I3iYWrf8olDgWXSF+k3+aZkcGuVF8PrEDco/eeB4ZB+9LbgPXMTEscftc+Rma+aA86GtRGpgDvtZY+CrTwazp1ctlBMqjy0OpNrGOIpSDNWyzNw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785767473; c=relaxed/simple; bh=rhIU1zG+Cz1JEJ/DZCxK23rcEZYVi7vpJbqoVBA+2qQ=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=NqkhwSYp2oCiQuP+ubX31XJEUU8hLbvAYllnKD0LbtZfC7hWyrS/1rK1TnqWMOl7NKQCNFL7oVVRFO6hCiweIX/mdK0nb7Ty3EKptl2OUEhBTmMwg8HCi5B5pOAEZYbO9ZcDsu2hyNdQY+8d3WdwjNtdFg3Cii/hmNmToaZUj9Q= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=EN5AsLZO; arc=none smtp.client-ip=209.85.128.42 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="EN5AsLZO" Received: by mail-wm1-f42.google.com with SMTP id 5b1f17b1804b1-4953de5be0aso14537615e9.0 for ; Mon, 03 Aug 2026 07:31:11 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785767469; x=1786372269; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=TzXAlvJrvz8VJKZL5THLFAhA3g1WFYpeVuZ+6qv41B0=; b=EN5AsLZOMn9+iUtyfCYtIKMbFvHptztVv+bPHFA279POyADHOG7dixnM1f0411liHX 1PrbJZBzQIwEditG2W6wojAatIoBiGxAJd/wLzW/kS179E72gKahzvmNEdr2PUHZasCF /uNQUqpJbkQ89P/Y3YFc8EYUonMWW+Ti2KnKGvvSBL86ycM/ev7qHiO0plpvIbSrTDir hArKa/sM1Ld4W4vKlF86AIKp1P1m65B5WnJ1vkEQZJi2w/8XuEpWp1lqMgU2XXDYA15z MoflB0MCxFRLbu2mLz4rQcHentmwCMrUmlY82EnYk+iqO6meeg3u9jdeu4BYD0pu7crr FTng== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785767469; x=1786372269; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=TzXAlvJrvz8VJKZL5THLFAhA3g1WFYpeVuZ+6qv41B0=; b=F99eMsIBA66WDEtMgHCbgkS0HdV6aecK/zuWi/L2KauKQDfYqV7buHMAkU53Yuu46K kF50mQ/AO7K1KsJfytrgRc94LdbJ9b6pHqjs9XTEzbz0aNiEJZdSv51tHa2B+i3VqPGU 5ezuR2kP0+gChtBKzdmCP0aD9vBEmyWNl8K0UJx80m+A2GL76f4BHH5jRbnZQkplwuLM HAZ2RoKyy4VxvDUxpl7jZD9GXRDhw2imfkEM7ZY8g5zVHGeO8kZz1iVj3CoPCBKw3FNV UJoeFr2fKcxGzBd3qv7BhDLxd+++XsBJ3AcUjCk3aFHPOITix+hD8V9UgaXnx1NjwuSi rQTg== X-Forwarded-Encrypted: i=1; AHgh+Rp1V4Qlly917clOoNKSKeFaWSDYi7gIsqj0EsH7hyF0lQE3KwF8e35Qas/gneW21HqYTEwo/GCXawAVyus=@vger.kernel.org X-Gm-Message-State: AOJu0Yx8FUz7GmayE/TdmzIoKI31nRehu/NOZEXyTGeNa+OsA/S0IJoz 9YSx+Lqbnm4toJKw79f1N2gdOK0z55Mkwgp4qKmXUgcxwAjELXx6SUSu X-Gm-Gg: AR+sD11j155yGcLOQq97eoM13bPidtdDfOWQufcjvMXfaDpCPxLxEudsXBUs70LkXmr EP4IhQMVZ72KkD84EY0G7IYP952Ttg7ik5EO+mCUtUE1lOsuBE2lII2yF3VR8kgSxL8+lh25HbC Pl6aXkQ/SRsCvYBtnw663YE3Cr1vZ9OijrRpNsiAS3Aibsyhz2CW9ju7zSCup18ScOhQb7D0t4K 3HdOcJ3JDi86D/4kKDhT631jbx6gb8IkZ7m1pm6uzW81GJ6rAQcDPBgZHFDoeCp9gIlWLfoRnJm WYJeeLHXqjrJeNAFKAE0pIKCU1wUpfpnRewzVa5smeAkuPkrjJDWrSKu8y6Y7+KOamyCyuxZNHl is9z+q4CZksDkumbtDLT536PNsDnwR5mzz5G0pAJrfLO0cMj33QG3uB2vI0u2OBzus03dsJ2P+v CypajYihGJ+Arh6k5a+CErN1D3VGauIPb7AqVSNMFeMdUPmXEfQHVqzk+rOYbVhYgHLQVeQxJHf RJEu/4vKKdkL1srewFFfBPommuF9CqmjLu3T5cJ2Q== X-Received: by 2002:a05:600c:214d:b0:495:3e08:ad19 with SMTP id 5b1f17b1804b1-4980c653c0cmr169146715e9.9.1785767469327; Mon, 03 Aug 2026 07:31:09 -0700 (PDT) Received: from fedora ([202.47.63.86]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49807b98284sm236575295e9.12.2026.08.03.07.31.06 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 03 Aug 2026 07:31:08 -0700 (PDT) From: Muhammad Bilal To: platform-driver-x86@vger.kernel.org Cc: jorge.lopez2@hp.com, hansg@kernel.org, ilpo.jarvinen@linux.intel.com, linux@weissschuh.net, linux-kernel@vger.kernel.org, meatuni001@gmail.com, stable@vger.kernel.org Subject: [PATCH 07/13] platform/x86: hp-bioscfg: fix new_password_store overwriting current_password Date: Mon, 3 Aug 2026 19:30:30 +0500 Message-ID: <20260803143037.93105-8-meatuni001@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260803143037.93105-1-meatuni001@gmail.com> References: <20260803143037.93105-1-meatuni001@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" current_password_store() and new_password_store() both call store_password_instance() with is_current =3D true: static ssize_t new_password_store(...) { return store_password_instance(kobj, buf, count, true); } so a write to new_password is routed to current_password instead, and the new_password field is never written by either sysfs entry point. Fix by passing false from new_password_store(), matching what the is_current parameter is meant to select. Fixes: 8646a3b5ee3a ("platform/x86: hp-bioscfg: passwdobj-attributes") Cc: stable@vger.kernel.org Signed-off-by: Muhammad Bilal --- drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c b/dr= ivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c index acb123985ede..6bd56d3f5bd0 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c @@ -123,7 +123,7 @@ static ssize_t new_password_store(struct kobject *kobj, struct kobj_attribute *attr, const char *buf, size_t count) { - return store_password_instance(kobj, buf, count, true); + return store_password_instance(kobj, buf, count, false); } =20 static struct kobj_attribute password_new_password =3D __ATTR_WO(new_passw= ord); --=20 2.55.0 From nobody Fri Oct 2 08:25:16 2026 Received: from mail-wm1-f41.google.com (mail-wm1-f41.google.com [209.85.128.41]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6D01440F75E for ; Mon, 3 Aug 2026 14:31:13 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.41 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785767476; cv=none; b=KO6aEbmbfXUe/GOIIG2ldQKzqoz+ZrOiNT0tYUI7P4PUsZuwUlk1DkxQ7IdNBDKqRNyXhO45b1ZfWPbBZWkbkBv5fHVe9KV1to5aFqMMLgA9uq+AnJmL1mBy7bhZEpIpogOgU2tGxGZ5TTxUwnV+cSGoZPfM84BOnYFan2YBfx4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785767476; c=relaxed/simple; bh=ZqVUWs3x1BgozxV3FrsSk7Lzh34dxSnwsmeX8ZrIYuQ=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=d2K/k/NiCBh4XFItvaJWH9+YGZX0g52GevEIQaU5cr+48Z4dQsXCwVq+MoJLUUaCVhrIl96psGWL2DHkH+UGcKyTwYv5/7+XOAwKUtQ4a21w+OAcZVeVHnla9WGbTCNn9jtDTwO1jwKyKCks9dGvVlMBcoGF52e3FRoOnGewrfU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=crzuaqhD; arc=none smtp.client-ip=209.85.128.41 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="crzuaqhD" Received: by mail-wm1-f41.google.com with SMTP id 5b1f17b1804b1-4954df200ddso14309755e9.0 for ; Mon, 03 Aug 2026 07:31:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785767472; x=1786372272; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=aGNNvpeBB2xFe8o+eAG+ITw+sBusoz0y2d8gJ/h4GCc=; b=crzuaqhD32tZylx5ndKwb6IvjJedmiZyrqlIP1NEQd0Q2lhDGUq34CcdY0i+LD7TdO HHlZ9I98cXfpHCGcVy0YqK13gDli1Hl1ObqaMxcztzMAVS2LRBQM5uskuNKJHRLp8j3W xCpovROFnXhsW172TcDfbR2shveaZc+U91lRkAtOO4I1JTTvJVC9oEA8ZHKdXFxo+JkI 4cezzWvEfb/fq69sa09DQaQ6vSvL9rkYZgk9GUNvUHL1GkTiGzruofIqlHKhgnaaH+qW sd7sZCzVk/KbWWf4YQu/cFcTz6Bl1rO2bo1YuyoMUawUUC08AH3IZaAJ8W0YCdxTngAn LJLw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785767472; x=1786372272; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=aGNNvpeBB2xFe8o+eAG+ITw+sBusoz0y2d8gJ/h4GCc=; b=TUdD8iVjHBnLZ+cOIZjH2JPiGALGWLafB//ee2mCqts4Z2C2I+r92od9fMK3SkXPza 1MzSwjwSNAIKnqf650eX9qUbH807s7UjudWSom1Hj6F7EejZAl7a5RQmduvTnpq4Blrb Ywqa2c9gW8Y5hVD0cU2xaF3eZXn4ypMqwMg6WyECwDn90rz3HPJg3LIdXvvJaG+l2hvX 3ZEiQBpKz/dg3NTaxSTzk+vp+Vfr1bG2MECl/PjzPcLghpuhwH4YR4/tc80E5ZHa36Cm 6ZAs/fSmEF3Ku3EAohge/uiv9/K8xjpj1YrUQ31zbj6GTY+1d1DWMdzoUPRxXO5LMsQc /0gA== X-Forwarded-Encrypted: i=1; AHgh+RrXZACUBVKAsjYut6QFA0yeH3DCRFd0b9ggdu+N0/njvng6Ukbz0PN3xJMoC+m69Q5KiudnmEWr6kF1Zn0=@vger.kernel.org X-Gm-Message-State: AOJu0Yy52InEhre/RmGkItnQVRLTnyVI1t/9meo0QocQTmhfRYDoA6LU EVJVMgxt7X328KCb4CD0dcGzbYOj++H6y7tzZcU7gTelfYl2OC8hueUR X-Gm-Gg: AR+sD12DiM5jytKH/AdrhVDdejyCyDxhLjMZuj4sLovP3z5vrMFOo4rWCNo6enIMYpC Bs2o2tjJq8GPm2BNWiqSvxlJlGfgsGKM/KH7Dm2hGNe2Xar3WG9GMmhuD9dW1CGLtXmEqO7SJeA snjzgvcqRvxv6kkXfyKKyYF5EazE3zMYe0Lugu/cCFxBlHwSfmTe9aCXkkUNyHKkHbdP6mOjYKw /hrJB0ZCJLJxUTmhvqOnnBzKclVqKCyl5+alQeHQilLPViD5cI0D7G6R+ADLqHVWniP2G7Jcnvw L1UL8ISvewyYRU3d4BoAPdkGxVndZjJxxRObp4qtSTfUKSCU4q9p0bR+cxGE0DNl3upOsKKWjot Y0yTb9QFHdB712AUFarxy8qxRMm3MTXC/BcGkDSJsPvSN7N4Qo9hVCMQKAK5mOpGhhenYG4NIIw mvtNf0kElsozoivMxZiyoWVn0+hfxRLE5AMJaCLXDGf0qI81QjGFxFaH48edDQv1pG0WztMl4zZ wTtinPVasWKcZnyllAlyGkBLNzVIZSx0Gu6K50qbw== X-Received: by 2002:a05:600c:a47:b0:498:1371:6612 with SMTP id 5b1f17b1804b1-49813716987mr143983415e9.6.1785767472196; Mon, 03 Aug 2026 07:31:12 -0700 (PDT) Received: from fedora ([202.47.63.86]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49807b98284sm236575295e9.12.2026.08.03.07.31.09 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 03 Aug 2026 07:31:11 -0700 (PDT) From: Muhammad Bilal To: platform-driver-x86@vger.kernel.org Cc: jorge.lopez2@hp.com, hansg@kernel.org, ilpo.jarvinen@linux.intel.com, linux@weissschuh.net, linux-kernel@vger.kernel.org, meatuni001@gmail.com, stable@vger.kernel.org Subject: [PATCH 08/13] platform/x86: hp-bioscfg: fix ORD_LIST_ELEMENTS never being parsed Date: Mon, 3 Aug 2026 19:30:31 +0500 Message-ID: <20260803143037.93105-9-meatuni001@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260803143037.93105-1-meatuni001@gmail.com> References: <20260803143037.93105-1-meatuni001@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The ACPI_TYPE_STRING case explicitly skips the string conversion for elem =3D=3D ORD_LIST_ELEMENTS: if (elem !=3D PREREQUISITES && elem !=3D ORD_LIST_ELEMENTS) { ret =3D hp_convert_hexstr_to_str(..., &str_value, &value_len); if (ret) continue; } so by the time the ORD_LIST_ELEMENTS case in the eloc switch runs, str_value is NULL (it was freed and reset to NULL at the end of the previous iteration). That case then does: ret =3D hp_convert_hexstr_to_str(str_value, value_len, &tmpstr, &tmp_len); hp_convert_hexstr_to_str() rejects a NULL input with -EINVAL, which sends this function to exit_list, and exit_list unconditionally returns 0. The net effect is that any ordered-list attribute with elements present silently ends up with an empty elements list, with no error surfaced anywhere. Fix by converting the current element directly, order_obj[elem], the same way the PREREQUISITES case already handles its own array elements, instead of reusing the unrelated str_value/value_len left over from earlier processing. Fixes: 4b2672ec71a3 ("platform/x86: hp-bioscfg: order-list-attributes") Cc: stable@vger.kernel.org Signed-off-by: Muhammad Bilal --- drivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/drivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c b/d= rivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c index f09489a085c8..704c69c18146 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c @@ -261,7 +261,9 @@ static int hp_populate_ordered_list_elements_from_packa= ge(union acpi_object *ord * Ordered list data is stored in hex and comma separated format * Convert the data and split it to show each element */ - ret =3D hp_convert_hexstr_to_str(str_value, value_len, &tmpstr, &tmp_le= n); + ret =3D hp_convert_hexstr_to_str(order_obj[elem].string.pointer, + order_obj[elem].string.length, + &tmpstr, &tmp_len); if (ret) goto exit_list; =20 --=20 2.55.0 From nobody Fri Oct 2 08:25:16 2026 Received: from mail-wm1-f41.google.com (mail-wm1-f41.google.com [209.85.128.41]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3DA5A41CB56 for ; Mon, 3 Aug 2026 14:31:19 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.41 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785767482; cv=none; b=J1MZY0x49V/LdI1AytkLggFPKtdQp7B6RBRowKqtWPdAWBxQ5rGnZXHo/kgUsFi/ELks9X4hkN7rFZRN6J3wLkBmP1fHxclUXK2PlOIgRaRydqzdlEvyOI8ftOM4HUmfpK68phsTQZALbBkPPXwMcKxepayDjJSLQcgcZMGXMgA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785767482; c=relaxed/simple; bh=aPETE3o1r0HQZA9wDBA5bpXSmM050p/rQxyZ/Pt3L2A=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=n5HLfgU1P8z/zLQBqWfzQfnDtPo7y+jEY+oVtU+QyTqNScajVT0n3sFypG7BXhGPDlIniNZCMqeb9TygkEsft8Jb/2ywGPevSh9oIFC93p0GCIgMzzmeYMw4nW85ocnS1ZhFJGwmOGdFYTDBaH05b7vYy2/ayynY8Op9J/qxqjU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=SO9oVCpM; arc=none smtp.client-ip=209.85.128.41 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="SO9oVCpM" Received: by mail-wm1-f41.google.com with SMTP id 5b1f17b1804b1-495437bb891so18186935e9.1 for ; Mon, 03 Aug 2026 07:31:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785767477; x=1786372277; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=I5CCpAh+m8Fx6ANrpP0jbYMsqCo/QP0tlHJ61+yZOVU=; b=SO9oVCpMeQguxxIa7MiRXp4c3nPHW255XH42M41WT9dEgHK3ATVNKn5ZmPCoyJ8uXq Y1AmMfEDRq9UcFMCoTga5OlmQD9nJKP+ClvI3BMP+8w9wdzmdi29qx1u9bOUXg8eNlOi bKGIVHgM9XyAwbELlpROyPAOlIVghdxEV7LYqsvzdLivbdSImmzSX2Jg+oj6S1lBCM6Z uE+ma7uVFXOk/dm1agvyrjCEU5uf8vYONW5//HjfEUZTOXv6a77qS632FoQE+UyrzlEg i7oAfQoijAUj/mKVo2wyRPKTJZDv4qtGqVJvgmHrvUE/oQayHhW27n1S2J8KXMW1P1NA rA/w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785767477; x=1786372277; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=I5CCpAh+m8Fx6ANrpP0jbYMsqCo/QP0tlHJ61+yZOVU=; b=SVWgqhMLSm8zgdcO1dw1PRQvTWx/6EzurTT2K5qhQqQ8YtGvgCEYZwkoc1/XxEnsdP V8qwAkm9v3xVYItVkx4PHJTPB5jT5qedsyClVC8cymX8iqfF/Kuj6Yel1yaJD8cO7pKY 0lh2nqVsCuBrTJ7EgOjnCA42ze9GYI98CLAtqHRb4AwCiH/4zGnITeQ+8E95yQLL2BV/ QWWpKCa2/ypuNDkKmT0e8rZfa0Gt/tinsZjwJs628YvXsIFXqUf5SEEVzRLE7M6LAT1Z 7vAGjKczuGJMHuHXs00g//7DS21Jg0W4eDyZugVqtcU4AjFHpFmg6vwi3AXpasEz/ZWr DmDQ== X-Forwarded-Encrypted: i=1; AHgh+RrGhFqPqqPt+2Qr4CQCeOv0XmPwo4xslUZRbw4TmHDNI7lfwm0pu8GVavgm+8VdFq1hW7Y7/ZJkznMDzYE=@vger.kernel.org X-Gm-Message-State: AOJu0YwmAiwTGzDSB9O6020O00HbnTNlfSCIc0mesq1KieJs4n9KWVFK nXmU5w6nudW4e+SAhb59IQcmmj5RpQXtP6PUeMfmBmm62L8NBiKM8ZGW X-Gm-Gg: AR+sD12Y8ALIbQO61GOEu7mbZ8ik/YqxZBXxiJL+MlT70wSITbuBtd14LQr5JSc8+tB SobNQ6+YS1AH3/lzgCwtNmofa23ZDIjsH5uaB9tBN/uzXNyp7KCuUZitpBSJuaTrUHS9lQrsJbi dPGn6WTIPP2LEUEfwW2x+cu7QllIaHkqJ08tAUhu7xm8V6mrd8iaNaKNSNIrL8WlGe490UWhA2/ ExZG0J9Avj6RynWax4Ks81Q9IJaiZPnRm4vZdZ0X4nHW5HvO/8ZssXQ7zF8oDm67rTXnGBxUEL9 HJXCFBCw1cV//wHmlS7SW73jhwgusDquFe/86QROVR2cz9V1wR/4PkV5SRSzwN6OkwsSyaxF1Yu /GF5RXKbJ2SJdGIT8vFHbr857WH8ukH7n+qBtqHQvNGwCUlpcLN/e1pVgc21ImSn4yb7FKQQkFN QqEGaY6kD7lFAlLLIzMwHfm8I8U4MoF9+ACmxmhpLKmFuvZBgRmPVLILyCt/HmbNVBAb1FHBK1R X5NIE+Eqo+aMPN9Erk6Izh+fSJsfRMMptdz6o3/9g== X-Received: by 2002:a05:600c:46c3:b0:494:1f7:8057 with SMTP id 5b1f17b1804b1-4980eb8d081mr174789585e9.1.1785767476532; Mon, 03 Aug 2026 07:31:16 -0700 (PDT) Received: from fedora ([202.47.63.86]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49807b98284sm236575295e9.12.2026.08.03.07.31.12 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 03 Aug 2026 07:31:15 -0700 (PDT) From: Muhammad Bilal To: platform-driver-x86@vger.kernel.org Cc: jorge.lopez2@hp.com, hansg@kernel.org, ilpo.jarvinen@linux.intel.com, linux@weissschuh.net, linux-kernel@vger.kernel.org, meatuni001@gmail.com, stable@vger.kernel.org Subject: [PATCH 09/13] platform/x86: hp-bioscfg: advance elem past consumed array elements in enum-attributes Date: Mon, 3 Aug 2026 19:30:32 +0500 Message-ID: <20260803143037.93105-10-meatuni001@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260803143037.93105-1-meatuni001@gmail.com> References: <20260803143037.93105-1-meatuni001@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The outer parsing loop advances "elem" (the index into the ACPI package's element array) by exactly one per iteration: for (elem =3D 1, eloc =3D 1; elem < enum_obj_count; elem++, eloc++) { but the PREREQUISITES and ENUM_POSSIBLE_VALUES cases each consume "size" consecutive elements (elem, elem + 1, ..., elem + size - 1) to populate an array, without adjusting "elem" to account for the extra elements consumed beyond the first. The next outer iteration then re-reads a leftover element from the array just consumed instead of the next real property, and the type check against expected_enum_types[eloc] fails on that stale element, aborting the parse with -EIO. This produces exactly the failure visible in dmesg on the test hardware, on every boot: Error expected type 2 for elem 13, but got type 1 instead hp_bioscfg: Returned error 0x3, "Invalid command value/Feature not supported" Note: this exact message string is shared by more than one file in this driver (see the companion patches to int-attributes.c, string-attributes.c, order-list-attributes.c, and passwdobj-attributes.c in this series, which fix the identical pattern), so this dmesg line cannot be attributed to this file alone without further instrumentation; it is included here as evidence that this class of bug is live and reachable on real hardware, not as proof this specific instance is the one firing. Fix by advancing "elem" by (size - 1) after each of the two loops, so the outer loop's own "elem++" lands on the correct next element. "eloc" is intentionally left alone, it indexes the logical property schema (expected_enum_types[]), not the physical element array, and each of PREREQUISITES/ENUM_POSSIBLE_VALUES is still exactly one logical property regardless of how many physical elements it spans. Fixes: 6b2770bfd6f9 ("platform/x86: hp-bioscfg: enum-attributes") Cc: stable@vger.kernel.org Signed-off-by: Muhammad Bilal --- drivers/platform/x86/hp/hp-bioscfg/enum-attributes.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/drivers/platform/x86/hp/hp-bioscfg/enum-attributes.c b/drivers= /platform/x86/hp/hp-bioscfg/enum-attributes.c index af4d1920d488..43beb639051e 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/enum-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/enum-attributes.c @@ -227,6 +227,8 @@ static int hp_populate_enumeration_elements_from_packag= e(union acpi_object *enum kfree(str_value); str_value =3D NULL; } + if (size) + elem +=3D size - 1; break; =20 case SECURITY_LEVEL: @@ -280,6 +282,8 @@ static int hp_populate_enumeration_elements_from_packag= e(union acpi_object *enum kfree(str_value); str_value =3D NULL; } + if (size) + elem +=3D (size < MAX_VALUES_SIZE ? size : MAX_VALUES_SIZE) - 1; break; default: pr_warn("Invalid element: %d found in Enumeration attribute or data may= be malformed\n", elem); --=20 2.55.0 From nobody Fri Oct 2 08:25:16 2026 Received: from mail-wm1-f49.google.com (mail-wm1-f49.google.com [209.85.128.49]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E76AF40F75E for ; Mon, 3 Aug 2026 14:31:21 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.49 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785767484; cv=none; b=Fug+vzAvsc55ZQwYuBYDaYarWJsJzq5qxD2G0lCI+HS5DjYrbP6CQp63O58X6/OvQF5F20woh5Jb8hKaVBdXu9H54utUJIdHeVHKabUDCxR1Xkq/HUem7i3OZn0FMzxlFcaG9jigWwqHLpX6kYCjJcgLuytzncMriupTqOhFYG8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785767484; c=relaxed/simple; bh=mT7/d7xo3H3nfPCihbxPgzMZLfcDW4NzWBe1wQtzgNo=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=hWgDb2ymLfpQARuggPUsecDO1nAkdxjhFFPCLFuka6lC2I9znhy3gpwjLyKfovvxiXkarJYaJ5BQPEEzyXA5nxLdlFDCG1TDz/RBjyVUiRfYWiYo0GBU8SiUOuySd9pmq+inpKnuzU7xHD+fYb6pjZldhGO+3LjWsMgrdL900gw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=ANrB3e/9; arc=none smtp.client-ip=209.85.128.49 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="ANrB3e/9" Received: by mail-wm1-f49.google.com with SMTP id 5b1f17b1804b1-4954a9e8490so15859575e9.1 for ; Mon, 03 Aug 2026 07:31:21 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785767480; x=1786372280; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=ndb/ZrZ5742Zc7Zv5as8TFdneRJ3/39sqxXLaYsiR40=; b=ANrB3e/9knuho2yGnbBS9IRfJMdYTHIUw3cmM1zHbIQh6Y7sE7h9bGXTPABRw+97Gw LLyLGNzYMC246eakAqUaNm16ZG1IbalAUQw/BNsNHgZMu0y4gUvrW7fYc25nr9fgXHdP 7ItN070XYaOOQJy7Bjb+AkajxFq5HVeOG1F3uCyC1Zh2mgtIJlN6b8mCjp+KTPnBizZK 54/pUPEnpsa8ZSSpNhRNTkMlm7jWDXLmfPame+pA7QK8MXvO13vJVNljUSIaCBxf0CSq IchSsLaUN87Zr9tEixt3G+qLOxFKPCOfeWRbbB13YBjjqD01CDwtX/ZT7owFmd9RVziA kaRQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785767480; x=1786372280; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=ndb/ZrZ5742Zc7Zv5as8TFdneRJ3/39sqxXLaYsiR40=; b=YR5VKMRBTMRGElVmTthrGgYFIXVXuVKfRQlKRCXhOWa4MNwajjF3ZF1Zjn0qrYUU9N JX6B4WLq9vdGHjMVl9cUxLNaW+3iBtuy7xLV7ioU61w8xAA3pIxtve6HvpMaFNoz2DKY iAwqhhAQycP+Djbm3/Eqf9igvppcIqEY+cciSGfVml6nMQBDaDtQFPYicIBOgiPueXDg HVcTbVgR97dr4aJfwSMa60JH63X+LpBsVpPrZBaJSzqALdoybFCF8MAH17ubzhX7lDz0 Xvqsu1CkRVnXqfQSiS8Su39kCYbbPkOF1W15tgBuYBkSewziEeWaNzMPWo1jviy73BEm PM/Q== X-Forwarded-Encrypted: i=1; AHgh+RqKIxlq3nv58sm0g+BGrWobfb35h5Vxb59JE/NS7qTky5NQpQlNr+7XwiE+/uVSCFr1RZmicECnKoYWTMw=@vger.kernel.org X-Gm-Message-State: AOJu0YztwFLfvIVsHNisDq0yAPD35zjYEmPmkUbMd294pB+s6e45+Cpu ywfj71b3vgduDKCnRocws739RxkXfiy145VWB6CaqIcZ8+6R3NbdDWt3 X-Gm-Gg: AR+sD10stCwQw8nWMGuJB8BEQ/H72kuo5RScojDGBDVPC2rat+b1k995RO7QmxNy2xV 0Bx0etRa1cKB2oQydRjJBe8TJPOl7643Wu5ANADw3axDOTr5avobmGy7q+sEypNQjNYebsyWETM wpFKiKk2g5f1qwlFNKRu9QGIlgnLaaNr5uoxnKu9jrdZAdo7LTRS9Guh8wd5vpah6/p3wQ6Nzv9 +Ie/ihJ1SRZYcdLyKM3B4qSG5iEBXoLSOPYDNkQocDqWzuvWf8clN5sCFMrHbpUfbRyWB7XsvCv QIBGwgAs1Jf6VkzWnOmbyAuck2L20huch2xgLNKGwGl4yWwI+b4sJ/XbL74AmPLbhYqfjFgcRND II0KtySusKDqc+69eAwdH6g1drmjUgrTEtKiuh9ZgfLLCkgnMSTVHdXME/afwcFAlQ64vYYLw0y hvrNG9aKlgRpl9VbtPKxJVTzWhQxd2xqRP5xC7Czxq6tndnTu58rt9zV3kT8zqfPBjeJFvYGoBZ nrW6pKWIwmtv91Jk6kl/eLNxfLvOSbsjrpG0ktAjA== X-Received: by 2002:a05:600c:a42:b0:495:69eb:27d3 with SMTP id 5b1f17b1804b1-4980eba0a6fmr208709925e9.8.1785767479778; Mon, 03 Aug 2026 07:31:19 -0700 (PDT) Received: from fedora ([202.47.63.86]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49807b98284sm236575295e9.12.2026.08.03.07.31.16 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 03 Aug 2026 07:31:19 -0700 (PDT) From: Muhammad Bilal To: platform-driver-x86@vger.kernel.org Cc: jorge.lopez2@hp.com, hansg@kernel.org, ilpo.jarvinen@linux.intel.com, linux@weissschuh.net, linux-kernel@vger.kernel.org, meatuni001@gmail.com, stable@vger.kernel.org Subject: [PATCH 10/13] platform/x86: hp-bioscfg: advance elem past consumed array elements in int-attributes Date: Mon, 3 Aug 2026 19:30:33 +0500 Message-ID: <20260803143037.93105-11-meatuni001@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260803143037.93105-1-meatuni001@gmail.com> References: <20260803143037.93105-1-meatuni001@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Same defect as the companion fix to enum-attributes.c in this series: the PREREQUISITES case consumes "size" consecutive ACPI package elements via elem + reqs, but the outer loop only advances "elem" by one per iteration, causing the next iteration to misread a leftover prerequisite entry as the next property and abort the parse with -EIO on the resulting type mismatch. Fix by advancing "elem" by (size - 1) after the loop. Fixes: 6f2c06d5a467 ("platform/x86: hp-bioscfg: int-attributes") Cc: stable@vger.kernel.org Signed-off-by: Muhammad Bilal --- drivers/platform/x86/hp/hp-bioscfg/int-attributes.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/drivers/platform/x86/hp/hp-bioscfg/int-attributes.c b/drivers/= platform/x86/hp/hp-bioscfg/int-attributes.c index d96e160953e3..5373af71549a 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/int-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/int-attributes.c @@ -243,6 +243,8 @@ static int hp_populate_integer_elements_from_package(un= ion acpi_object *integer_ kfree(str_value); str_value =3D NULL; } + if (size) + elem +=3D size - 1; break; =20 case SECURITY_LEVEL: --=20 2.55.0 From nobody Fri Oct 2 08:25:16 2026 Received: from mail-wm1-f48.google.com (mail-wm1-f48.google.com [209.85.128.48]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 27EE14137A4 for ; Mon, 3 Aug 2026 14:31:51 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.48 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785767514; cv=none; b=bsaG+OrLz8pzJFHsyx6ih/P7llPsurLiMXJdwred/+LZLHCQyIxWsQ8Es+PfdjXDah8BtAlbz5BcKH+/30knb3dmDQN5CiRpkGfb3AgIm0tVbLStb+n8iwTbcJsX3pCzjymJ1lF9PyBivGeIulSKJQKHSVTWqIpYXPvpU9X/nrI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785767514; c=relaxed/simple; bh=mbTl1m4q/B0mmfJqUSHx3puQD1k3DIBxLZfuWKkL4MA=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=LLyeFPIkxjWjudbgB6Q84HCqYonkmRZvAnwmjx7EEqB5Lwy74OryulAbzJ4JY2d7jgOCRaqofbYdLvskPHaRaOeo8ZWpF4ss5WlFiXerJIxLcJPA6/DiSUedx3id301mEfzyDfAyP/D0nf8rb0J1JPVvRZEFLnNKjNLzR2UmWpQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=auX57uo2; arc=none smtp.client-ip=209.85.128.48 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="auX57uo2" Received: by mail-wm1-f48.google.com with SMTP id 5b1f17b1804b1-496b7622a83so14267675e9.2 for ; Mon, 03 Aug 2026 07:31:51 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785767510; x=1786372310; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=zNxBi0gHfRrbC33pAvz30lhxp0rXTHoZRpmh1XXR2eM=; b=auX57uo2tZFgjzyG2o2uCFwKPBWj/Je1Q7mb+togKe4a4TyYapFV/ggNh4GHgVTiXz UA221y9Smrx8IqN/Wo9VTodGwh4v+KBB92H2rO4SdD/ODjrBFZEZjGjHV7zCXme1GE/t RGjRLiG5EYK8JkEK26yNl1ernN/8NAvxUlV/SEGGZC+PcsishP5wipoKnrJ+4kGD1BLR RX8n52PvkYebHk3gqUDC7Fu6a0JNNsNY0rTF/BNxv9nn7a/BN65NvAF8nQhZdibHWvAA f3SmoM7/Mih8Njr4iPg7atEYuq0ZUi1WI129gzyc+bo/wP6rwXloPCiUwrE8t4zeYs3y WGrA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785767510; x=1786372310; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=zNxBi0gHfRrbC33pAvz30lhxp0rXTHoZRpmh1XXR2eM=; b=bUPYl+RClEQ6t80wCHm16mhTDeW2fLGYeRTyMrkGdNjtyEpB0vkw7+/4ddQzBeaLQa 8ynCz2FsCkt92couUwVFZXU94RcoEHa+1CsoweRGPgGCNQhzS9qpfZs0rfSXVfv7Pkkd om+U6+EbTk7N9Z27kfHWNhqZhIoJ+b09vuPmne1LhFKn914eMzgnhkejx6MtCOOYTOuT MZaE1bgbb2fhWTw4UuEWVbgvMKyTCkLbjL+u0J4ZXVr7gXUm2bX8tPyzO7U0CbWh1jOS nvsDKuAe+S30IYq9PP3fB5zjWsWck4t+GC5rVQdglXsok9rYN2FB1phYszibKi+dI/GC VDZA== X-Forwarded-Encrypted: i=1; AHgh+RodbcYEgEk1CwLO9+SzQr6CyznLKe2CVYn3+THrwqe55p2luMPbFAglkZ02XNRQ89BV6XaSNQLrDtJ+VNU=@vger.kernel.org X-Gm-Message-State: AOJu0Ywyygj1MXcxH560Ec/DND2ANsGuoPfqD69mNvBRRqWb0olzepKR 1aSVmx9Cb7tuQ2q6GYdLqyWJ7EcGKge02yUOGY08ZJEYTfC5OPVMbBny X-Gm-Gg: AR+sD108P0tFUPECxpXIWDLuBlQJV0XNTmsCWrrhxPanDuQ+eHfsIJOkl/lMzQ+HrWv aAgq1JcAuZNSNxcEnD92Trg4m9LKuC0xC2cgSCOEBSwGye5b77hY16nyukj8B1EzfvMJIr0ZqQx q8LJtp3RTz4qy35YWnZa7oD9d7foRxA6LCdaDiXKKb4JfsvB+eS2BH2b3Kks7f2c7eJW0UGCbaf t606vMpxFM1B1OVSi8O8EBDijNsflfei3tTabbu+cPeSVkvPu/MdmDgotR1lZXqa99WCFRZDpuK +N2HShYG/P3CTHKyLmwAEdO9erNGn75M2vHRURagnSiMjcQJ8LqIECSORN3BBv3LhrbXMIDuML+ le1zGPIdVoOZi9mXCeLMpdTezWgL9MEDHHJRuGzZJPRl8wGWsG0Xiq5hnp8skaOGOXhm5GD6wh8 j3PPZPTZFT/k8TIHGL4mUpMu7SnLEWOISeJbc4T30SKRPoMkcGyFK8enWo7Bvyuvy84P1jOv8iW BMm/bjMhjbt2dd/P8FHcgEmauQ+sIk40wjBRa0WBHoo/LBuAxhK X-Received: by 2002:a05:600c:1d1a:b0:499:49c6:bfb7 with SMTP id 5b1f17b1804b1-49949c6bfd8mr2265555e9.7.1785767482896; Mon, 03 Aug 2026 07:31:22 -0700 (PDT) Received: from fedora ([202.47.63.86]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49807b98284sm236575295e9.12.2026.08.03.07.31.20 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 03 Aug 2026 07:31:22 -0700 (PDT) From: Muhammad Bilal To: platform-driver-x86@vger.kernel.org Cc: jorge.lopez2@hp.com, hansg@kernel.org, ilpo.jarvinen@linux.intel.com, linux@weissschuh.net, linux-kernel@vger.kernel.org, meatuni001@gmail.com, stable@vger.kernel.org Subject: [PATCH 11/13] platform/x86: hp-bioscfg: advance elem past consumed array elements in string-attributes Date: Mon, 3 Aug 2026 19:30:34 +0500 Message-ID: <20260803143037.93105-12-meatuni001@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260803143037.93105-1-meatuni001@gmail.com> References: <20260803143037.93105-1-meatuni001@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Same defect as the companion fix to enum-attributes.c in this series: the PREREQUISITES case consumes "size" consecutive ACPI package elements via elem + reqs, but the outer loop only advances "elem" by one per iteration, causing the next iteration to misread a leftover prerequisite entry as the next property and abort the parse with -EIO on the resulting type mismatch. Fix by advancing "elem" by (size - 1) after the loop. Fixes: e6c7b3e15559 ("platform/x86: hp-bioscfg: string-attributes") Cc: stable@vger.kernel.org Signed-off-by: Muhammad Bilal --- drivers/platform/x86/hp/hp-bioscfg/string-attributes.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/drivers/platform/x86/hp/hp-bioscfg/string-attributes.c b/drive= rs/platform/x86/hp/hp-bioscfg/string-attributes.c index fe5a9a3a4ef1..5abec8995911 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/string-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/string-attributes.c @@ -233,6 +233,8 @@ static int hp_populate_string_elements_from_package(uni= on acpi_object *string_ob kfree(str_value); str_value =3D NULL; } + if (size) + elem +=3D size - 1; break; =20 case SECURITY_LEVEL: --=20 2.55.0 From nobody Fri Oct 2 08:25:16 2026 Received: from mail-wm1-f44.google.com (mail-wm1-f44.google.com [209.85.128.44]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 13FDE3D75C7 for ; Mon, 3 Aug 2026 14:31:29 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.44 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785767491; cv=none; b=YfuUln5JcYk+X6Hc+mPL2c7IRr7rjf+N2nXVGsqMclVwxOrfSxDpsPyTMxP07+CZT7oD3ZGYCze33D8yRx/ZijAHJMZDWQqtfw6xtQIGfOFPIVu+NkvK89L77Ib/zHP5YYAqP33zSeznDDdIuK+AnJ94LZq0A29gcjnJ1EOEXXE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785767491; c=relaxed/simple; bh=arXYzsOl1OkfcjkMtMDJ5cgQlgHX5faJ6mvfLb2jvRw=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=CNt0HbDuaqvv8ySS/SHrOdFQPM3cjBTbz2bW5KtOHsgvmrFFf/kg58G79hYDklZF1Jhe/S9YozoECFAMmJyEtPppb8CyPHYJ+5V94maMW6sAGl5nuSykt/cS/rfrhkLkPw81tXsm6zb3ubxrTAHZok8E5RBZiJqcHAgstJu4/4o= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=Z5lIjtaF; arc=none smtp.client-ip=209.85.128.44 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="Z5lIjtaF" Received: by mail-wm1-f44.google.com with SMTP id 5b1f17b1804b1-4980fe6b3beso10676315e9.0 for ; Mon, 03 Aug 2026 07:31:29 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785767488; x=1786372288; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=pRYAshv6bCkW3StAMRtfaFS8SltMPequV+AOq12EztQ=; b=Z5lIjtaFUtk11Di+K4rJ6WBu0izPFWDpllTVnWYsoZj7PbzNhUWFWXp5lDUM+ONSLg lJ1Xe//gpXw3okce53z2Mp0C6lYW+18smRhgI+gXA0kO0n6ABlqi4awZfnyqJa0t5ZKU GURyeB5nVGoZuQHhnwjzlykpjXPbjRoHM4YIvyQfjyWWzssClxOfZgXKsiSi0ODi2R3g lU+85YZLwQiNVz6jK7HM0ClfXuEcUh52mLbJyTZtuxM/BKMOzTODHy3xzBLlIaDBQCA1 LzqNjQhSfyxsU1xCrZsi1T8OO8/mv+WMucUZcuQKjkTInQAKSrDAdFrAMLOsvaLZZJfh 0O7A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785767488; x=1786372288; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=pRYAshv6bCkW3StAMRtfaFS8SltMPequV+AOq12EztQ=; b=mecdba8ySforyWRGx1AZMNPQOKsSl8YKQ+3CbMx2cB9MUimPFSM3ewJ6KK31GlD1rm u1Ex5Ahp2zaC5p+BC+mZAVUQ4OoIysqzQOXgV+dGQ2QZiJiOAYkk5lPcZsvHAR+O72rg pXCfVolnlRM1B8op0JIIvX8hfkhKvU3Ip/sHsP9abD9kg8/3ypsRESdDpwFOhP0wrBJ5 xgv9+UKwKOueNL5+xU5+M0j7dPKP7HthCNPoIHXLABZcqBniM0jDiiKXL82AZ7jBiBzu 5aS3Rthy8W09gH8fdb3k7XOWg+5hafMb0FQWBc2Ng0lo38cs+BsfKeksjikL1gneQxBM BADw== X-Forwarded-Encrypted: i=1; AHgh+RrduWgBPmIwMNjt9Jz65E+x9kagH5D2d98kd0Gq5CnrP7vcynIhF3btbnTdlp1QPgwojCRwfAjCqoefcm0=@vger.kernel.org X-Gm-Message-State: AOJu0YzrLczgMpsdvDQKIhUmxTGvkwbKwmvTTjOqX0KMVMLpRG+eC6lF JUM/90XHYoqQC5hXihLNnYh5EEFSwJ2UFVxKYYuYCvOm6WPRrsWrnpQp X-Gm-Gg: AR+sD10gGMBDfFteoG1mhb0qC/yM0/cevDVk9zk+6itKxVc3BnaaPIasK5bKIa9DT8v bqOUREqZZTbwm/El1DWdanwaKYf2RivWAIZ+lUsJyp6JrN832bHjJq8gLIwo+d3FaPxOVr+H8Op uZxpgaoU9E2gbt2hj0ccVsOZX9gtId3TlxYhX0Yoh6RsNE/tHIaqH+sE7xyJHcHyBU7CvYjPzhe xDQPrx8H/49VX1wRm4+fryztLJECEDleVENiVwwksvu3GLu9+U0j3LarXWRxpWYLF0xr0s31pbc n4/LTGrNxt0oN3LszPjwA829C6F55q2QkedLMjAbcP4iKukwF/BTnaOUs6woQmOZxW90jE4GiI7 16pPZzJLYpr6fmd873KamuyvZN5pSTJffXy3mnkodD4LrPn2/aJeir+OZJGYZbXqR5uIjI4b+m5 HqHOBdlDKBYzyEuxB2o9gw1AA6il1C97Kuwt4AC7uDIixCtHEEtQHacCsdcoFnOkpqW/6NmTRq+ gAd90aqatBzUUtC1hw0woVhtD+6Kdj0MsWZ26ax4g== X-Received: by 2002:a05:600c:a42:b0:495:69eb:27d3 with SMTP id 5b1f17b1804b1-4980eba0a6fmr208724155e9.8.1785767488101; Mon, 03 Aug 2026 07:31:28 -0700 (PDT) Received: from fedora ([202.47.63.86]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49807b98284sm236575295e9.12.2026.08.03.07.31.25 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 03 Aug 2026 07:31:27 -0700 (PDT) From: Muhammad Bilal To: platform-driver-x86@vger.kernel.org Cc: jorge.lopez2@hp.com, hansg@kernel.org, ilpo.jarvinen@linux.intel.com, linux@weissschuh.net, linux-kernel@vger.kernel.org, meatuni001@gmail.com, stable@vger.kernel.org Subject: [PATCH 12/13] platform/x86: hp-bioscfg: advance elem past consumed array elements in order-list-attributes Date: Mon, 3 Aug 2026 19:30:35 +0500 Message-ID: <20260803143037.93105-13-meatuni001@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260803143037.93105-1-meatuni001@gmail.com> References: <20260803143037.93105-1-meatuni001@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Same defect as the companion fix to enum-attributes.c in this series: the PREREQUISITES case consumes "size" consecutive ACPI package elements via elem + reqs, but the outer loop only advances "elem" by one per iteration, causing the next iteration to misread a leftover prerequisite entry as the next property and abort the parse with -EIO on the resulting type mismatch. Fix by advancing "elem" by (size - 1) after the loop. Fixes: 4b2672ec71a3 ("platform/x86: hp-bioscfg: order-list-attributes") Cc: stable@vger.kernel.org Signed-off-by: Muhammad Bilal --- drivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/drivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c b/d= rivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c index 704c69c18146..6696255738ba 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c @@ -232,6 +232,8 @@ static int hp_populate_ordered_list_elements_from_packa= ge(union acpi_object *ord kfree(str_value); str_value =3D NULL; } + if (size) + elem +=3D size - 1; break; =20 case SECURITY_LEVEL: --=20 2.55.0 From nobody Fri Oct 2 08:25:16 2026 Received: from mail-wm1-f42.google.com (mail-wm1-f42.google.com [209.85.128.42]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E17FE41DDF8 for ; Mon, 3 Aug 2026 14:31:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.42 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785767494; cv=none; b=eGgZ7t8U4swMFeGvk9YvecJ+AYluCUdLVsraNtJBo4Jka0vNCm6fGB2OYKG1vwmg7ZKqUZFhbnmSU9aqalkx1LaBUIky9oiR89jS1LmQjtWUfeKovkJria9Xrc9T2Ahr8c/s51jJRpqwvAp0DEil+uZg2tSN2j/wMl1vXAKj6r4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785767494; c=relaxed/simple; bh=bxA8J6/qIIfaCWTOgjW8WTYcWhqAJeYz4cR1gJwp01U=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Bk0B2Dbi/FhyO2Sx843iJrW9oX7pgqDfmbXKKv000ZgJ9fiW0cZuYCr9TUCnCggmI/UUtZKGpPsvWjkIc0Z4oFowdRSvYmb1qY7WwbRaazhg0nwrSmPPazPUPJdWZEB066ZxRnjfbAtjYaay/MAphYJquWZwY2HgBUDmExGorwQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=n75G9mHi; arc=none smtp.client-ip=209.85.128.42 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="n75G9mHi" Received: by mail-wm1-f42.google.com with SMTP id 5b1f17b1804b1-4954afac04bso25861225e9.0 for ; Mon, 03 Aug 2026 07:31:32 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785767491; x=1786372291; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=aP3AzbHc5YQoHN80VU5i3zw1DBkXU+MO/jUixWC22QY=; b=n75G9mHi6Hk0eaxOlM+uosEL+Ab/+FyB4PZEH6zRgOTxBuKVoDALRfcpRj4v4BVSGO Rw+xjlNaUYmz0WUmH31ybt27W4BNEbrt62NB9QBZNkihfx/cmrlqzGFe9nY/H77o3YJu QoBwjiP2y3MI8vUVJT8cJZ1M1XqbaVSXqNs99TT0wLb6pMthyKctXLEN78IWLhZHFtUs gWmgrlHe1C9TgcvIJmk1my9csBypZluiiD9i7MaAvuKMYvJUrGajyQgPzc+klvLY+RCq npJs2J8kYeXM2kte4lqHaHKJwdElVkMeGzzLzK2WEASY2IMHUbbWJ89y8ScRg+YLk4wX 7SPw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785767491; x=1786372291; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=aP3AzbHc5YQoHN80VU5i3zw1DBkXU+MO/jUixWC22QY=; b=qOGX4f0AiQaxNbYFlRj2cPSbyaDZA7dE+3jCknJkXrAMHYr7K1ADK6XqzTIixTM81g ve4pkAuf2qKsowDQT0+jQ9GhO0X96UNc3XJIv5ZLdcNdl/YguPOsoZrd5/8joOw7L9nC oDLsJrMTx+W3CvSmZSI30IDp0GzhmqmBlRbaqPeuWwsIlIjxf/lhzUDfyNYApormJBcl YfJ/dWMYGpKCe1iYtSX5d4ZcPZlDNxJSTQ0zqBFS8llTrTtI64iVnB7vGKP/yGZJs0g5 7xIHYMfocB3bdrOJPgLvrmRpah8oIPHoBa+Ky9SEUasHwqOOLCnec97GE/sefj0KSH88 5a3w== X-Forwarded-Encrypted: i=1; AHgh+RpOvFzVQ328SsW21MlTdS+ym5OZUHruqDxRZKedsDGTnZ4x/+mTjZb3q8CgAr2Mf/v8FomNgvB9SykymuA=@vger.kernel.org X-Gm-Message-State: AOJu0YyDpB9LwNyao4C2InFvsfhzUP/LY1mtfoxbfgH4L2EjDk7Wz2V0 60kdqg48k9pHw2C7N1IXlRfap2dmwOK5/fWxNQqDZA+ltRbQV2F3MSLp X-Gm-Gg: AR+sD11ZkTV5FGwKoB3LCXyJWrVTmoTJPf5qIna6m0UU8ibI6SH8HGv3Fa9FIhaFZ4q puAQQhdELbIi+7ekd8ZTrPDRkEyUhKMt/GP0H1Cb0/3W5hp6VNZEEiSlZSkznfre63YoYJwSKjY JbosbyHi7IQv8g8CM0m3xkpEFpBdIyLUdiBlv/x6xO3QWGhusQcX5dBiOjnBKTZWPTEKxJraFWB sd3uky3dHnU9YTanjaF9+1vlWFFlvv4kW6xw29rNHhh9l0IDTvgsqgNYmmzow3IMrA+5u7kS5Mx 75nwp2u4UpL+gjMd6eIQgLz3Va3VXvHXsqd5kKQ8FlEeacsCAQ138XJiIarfg5wXNPXcZkKL1yG OOH9GqDMJQUxMcPWXTC9rm3SgMXrJ4mEwnz81u5gPoucxA9Jql8QIIbYEjHekQHLpg3069ANn4S 5tHUEPC6JqM8Ks4tFq1nbjFJtEU92kWXC9ZTOG9h3nscV5XRZecqsfkWQi1TZYGS4sZYatcqIXC HqINCJZ2K4emrjMgvj4wu3pth9at22TBkThjVHB0w== X-Received: by 2002:a05:600c:5248:b0:495:78af:78e5 with SMTP id 5b1f17b1804b1-4980c66c80bmr200642125e9.1.1785767490982; Mon, 03 Aug 2026 07:31:30 -0700 (PDT) Received: from fedora ([202.47.63.86]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49807b98284sm236575295e9.12.2026.08.03.07.31.28 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 03 Aug 2026 07:31:30 -0700 (PDT) From: Muhammad Bilal To: platform-driver-x86@vger.kernel.org Cc: jorge.lopez2@hp.com, hansg@kernel.org, ilpo.jarvinen@linux.intel.com, linux@weissschuh.net, linux-kernel@vger.kernel.org, meatuni001@gmail.com, stable@vger.kernel.org Subject: [PATCH 13/13] platform/x86: hp-bioscfg: advance elem past consumed array elements in passwdobj-attributes Date: Mon, 3 Aug 2026 19:30:36 +0500 Message-ID: <20260803143037.93105-14-meatuni001@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260803143037.93105-1-meatuni001@gmail.com> References: <20260803143037.93105-1-meatuni001@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Same defect as the companion fix to enum-attributes.c in this series, present here in both the PREREQUISITES and PSWD_ENCODINGS cases: each consumes "size" consecutive ACPI package elements, but the outer loop only advances "elem" by one per iteration, causing the next iteration to misread a leftover entry as the next property and abort the parse with -EIO on the resulting type mismatch. Fix by advancing "elem" by (size - 1) after each of the two loops. Fixes: 8646a3b5ee3a ("platform/x86: hp-bioscfg: passwdobj-attributes") Cc: stable@vger.kernel.org Signed-off-by: Muhammad Bilal --- drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c b/dr= ivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c index 6bd56d3f5bd0..9b989ef756ea 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c @@ -321,6 +321,8 @@ static int hp_populate_password_elements_from_package(u= nion acpi_object *passwor str_value =3D NULL; =20 } + if (size) + elem +=3D size - 1; break; case SECURITY_LEVEL: password_data->common.security_level =3D int_value; @@ -367,6 +369,8 @@ static int hp_populate_password_elements_from_package(u= nion acpi_object *passwor str_value =3D NULL; =20 } + if (size) + elem +=3D size - 1; break; case PSWD_IS_SET: password_data->is_enabled =3D int_value; --=20 2.55.0