From nobody Tue Sep 29 08:25:34 2026 Received: from out-170.mta0.migadu.com (out-170.mta0.migadu.com [91.218.175.170]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2E0E03D9DC9 for ; Mon, 10 Aug 2026 13:23:11 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=91.218.175.170 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786368192; cv=none; b=aBkWrMxVsPtGzEnOR1FgGhWn8ypH7x+Mh0IJzhXYlbYEqACsNCcf2iiGPxe9U0O0+2/4bWU0mAV3J6xy9PTv9W71n84pMPwoY+m+K5IMbJKSQNUVYUzoht/92eahTFOeCEFH9617bgAAUnRYrZdcOUtZo+Lzopnq7H/3Eehilz4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786368192; c=relaxed/simple; bh=OYPFC/gEPzlUdWJJcy+x0x4slZGuAu5zp77YNifcl80=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=OtDfGHu3tv/9qAngK5lK6AYLYCh4jml44mDeKAzOO9PoP9ZqNAdyYRBzQdqPJf1vrhccBdkdUGLWFh3MkqcFg6Ha3EeSvjLiid+x46n8hhzr5i8SGSz1VMKA29p64UHJt/9AqN0Obh2rGNRhttcEqLueiOserrGxMvCG+nunKvc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=JeRrOhaM; arc=none smtp.client-ip=91.218.175.170 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="JeRrOhaM" X-Report-Abuse: Please report any abuse attempt to abuse@migadu.com and include these headers. DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.dev; s=key1; t=1786368178; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding; bh=4Q5WZ90Z+RvgAZ8GPWsZf/FI1jZNc1ucFZ5oCDV7F0o=; b=JeRrOhaMAPoENtTjgJ4xlzv/+ciD8na6jKRYjzqyByaHTohyqdZW2XE1u280CrmjRl+tHI +NZvuu/2zITvvwmUNUeotxPUbE2xoc07CnvJFM3xnSgX/ui11M+LKlqzbUzmUrS/3fc2D1 6oUhUUZ8fh0bzVOub7Hi1BBfyCLIYNE= From: Thorsten Blum To: Mark Pearson , "Derek J. Clark" , Hans de Goede , =?UTF-8?q?Ilpo=20J=C3=A4rvinen?= Cc: Thorsten Blum , stable@vger.kernel.org, Mark Pearson , platform-driver-x86@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH] platform/x86: think-lmi: Fix current password length check Date: Mon, 10 Aug 2026 15:20:20 +0200 Message-ID: <20260810132018.156868-3-thorsten.blum@linux.dev> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=1638; i=thorsten.blum@linux.dev; h=from:subject; bh=OYPFC/gEPzlUdWJJcy+x0x4slZGuAu5zp77YNifcl80=; b=owGbwMvMwCUWt7pQ4caZUj3G02pJDFmVF4TMHZcsa+jwznKIe3xIyeGm9frgCwf392mrndkx+ Qnji+VSHaUsDGJcDLJiiiwPZv2Y4VtaU7nJJGInzBxWJpAhDFycAjAR4UJGhjUd4hsviql3/tlv ZuB8ZePu2bn/PDls/7i8crrctGd//GuGPxxnpdZn9m9RubHgcOb/Y5nNb473bHvQHfnwp85VIf5 pPDwA X-Developer-Key: i=thorsten.blum@linux.dev; a=openpgp; fpr=1D60735E8AEF3BE473B69D84733678FD8DFEEAD4 Content-Transfer-Encoding: quoted-printable X-Migadu-Flow: FLOW_OUT Content-Type: text/plain; charset="utf-8" current_password_store() checks the password length before removing the trailing newline, which can reject valid passwords that are exactly ->maxlen bytes long. It also passes ->maxlen to strscpy(), which truncates passwords without a newline. Use strchrnul() to measure the password length up to the newline, then copy that many bytes and add a trailing NUL terminator. Fixes: a40cd7ef22fb ("platform/x86: think-lmi: Add WMI interface support on= Lenovo platforms") Cc: stable@vger.kernel.org Signed-off-by: Thorsten Blum --- drivers/platform/x86/lenovo/think-lmi.c | 8 +++----- 1 file changed, 3 insertions(+), 5 deletions(-) diff --git a/drivers/platform/x86/lenovo/think-lmi.c b/drivers/platform/x86= /lenovo/think-lmi.c index e215e86e3db7..860224dc8c21 100644 --- a/drivers/platform/x86/lenovo/think-lmi.c +++ b/drivers/platform/x86/lenovo/think-lmi.c @@ -436,16 +436,14 @@ static ssize_t current_password_store(struct kobject = *kobj, const char *buf, size_t count) { struct tlmi_pwd_setting *setting =3D to_tlmi_pwd_setting(kobj); - size_t pwdlen; + size_t pwdlen =3D strchrnul(buf, '\n') - buf; =20 - pwdlen =3D strlen(buf); /* pwdlen =3D=3D 0 is allowed to clear the password */ if (pwdlen && ((pwdlen < setting->minlen) || (pwdlen > setting->maxlen))) return -EINVAL; =20 - strscpy(setting->password, buf, setting->maxlen); - /* Strip out CR if one is present, setting password won't work if it is p= resent */ - strreplace(setting->password, '\n', '\0'); + memcpy(setting->password, buf, pwdlen); + setting->password[pwdlen] =3D '\0'; return count; }