From nobody Tue Sep 29 04:39:33 2026 Received: from mail-wm1-f50.google.com (mail-wm1-f50.google.com [209.85.128.50]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5D2E6432319 for ; Wed, 12 Aug 2026 11:18:39 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.50 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786533521; cv=none; b=fFTILMQeABH0rWiYQhEIvp84gYOyaKQTohoUxep2eL8Lsd5i56X+epg6ldSJHi8Zapa5nLc0ieGhJ4UrsrYkXPBzerR1KnoG77NYVUgxQqZaU8bymUzUmF2W/Qup5YbXXZyNAO3FFiXtFScAbgcb+UVTKHeHSn1HuWWlwq4qNOY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786533521; c=relaxed/simple; bh=OA1LKTN49b5FUMf9V/yVYL0uyXf1T9fnPQ99xO6TDc4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=H1S7fa0cllU0WUpFOn3QfLgMqyXuPrzD0P9ROHlv0XFMXY9YRgrMxo12ZOFWGqLbaoB1Gx9k5kOIuX1Fs5VvGKAnWrN/WrTK9zU9ujNFZDtxWGDo7xwYRYYiYJaSd+PyOeTyy1tLWO2B5yOA6QgKdy9kCqg/FZ3DGB1x6a5O0mk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=RY76nLs2; arc=none smtp.client-ip=209.85.128.50 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="RY76nLs2" Received: by mail-wm1-f50.google.com with SMTP id 5b1f17b1804b1-4954a2e73a9so4316805e9.3 for ; Wed, 12 Aug 2026 04:18:39 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786533517; x=1787138317; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=9gdrr7AdAYBlVDbcFRIgxo33EdXDmWd6yiBKqM/w3XU=; b=RY76nLs2XsvTwijTpGpEsEXMAYwayhYLEP6YkKzDwsASK0zSiHCv0v0DQaaaPq0uDz 9uAYuGJtNp+ONLCR109gBpNLrQ73C8tmePqrjqS0Xtj7bi4iCNEU0onSJb617GeVl4UN dEoDe4gUQVDf2YZ3NaA2ir3FJEUUjn7p7QvjI648xLWM92I2fSjEMZr4gP9ez7jeAKnM /NQFfLKZKs26qmlbgumab3lLItPn6KKCpx+imba4vPN9fupotLjWdbuuRL4dIv6rYzOM 6uQ+rbXNVJOatWNBA06jSr76JWEhKXeLmpQiWLpB/xABDtzietcV6870B/xo8he0OuBp 1QXw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786533517; x=1787138317; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=9gdrr7AdAYBlVDbcFRIgxo33EdXDmWd6yiBKqM/w3XU=; b=oFkAJD1AYBKkg8vb6+3dCAuqbG7MedreZOu3VYda1e0ijVRzlCUwmCK4nuxRmjUPlo tQUNd10UcapuKRp7NzXyGgZdpwAynCKfIMebzJyExCPckX//ZkClFTRnhXIDrurBu/df BZmhQiUrmte8wDs59e60SgMvGLI7XaZ8b8s+7MNHCTk3sIE7XaoBIF1YjwCAdwZoD5pX ox+mRlZg2mirc8oj/KSjEBdKfiuTPRqU4MiKUvQtFR3VVO06jS/vgJgHkRzjm5REbKcz 4/QNum9FfLqryGXXJ7YqjXheTPN01u46GJu+XXR+WoZPKas/wnZ8hP12ZELFRXzR4Mjm aQmw== X-Forwarded-Encrypted: i=1; AHgh+Ro57i8Q2GaevgrQUmJyBFinFmVYVXjpMlOYOW9Hp8VbxyptBcKwA+TyX/YQpRtdgVVkIrD90psolA5o6jc=@vger.kernel.org X-Gm-Message-State: AOJu0YyLh6qgN6uL7hGRPnVaxrk5bsNT+UbPw9XK4KNJYRNWbjgCtj5Z shwkdzn5e0hCgrudAGQeBwEj0TFXlgqD9QZkn/PVqBG2crCTw2XRqcwF X-Gm-Gg: AR+sD10UwIdRDQwOIc/6xpJtne5Gd8gA4B6WGc8P/AjVyuq9pi3ohzAyT+TAx72DKXi Q3gv+4U7V99bl/a2XtfIT5P0WiXyoYQ2k/DO31lfN4bLw5pYi2Qqa5c2PjPcPty8ntZcIu4i+Xr 0g2WTYKEbvvzvZLeGzKkT9e1tVDnWthpXJrFFJNz7BNSGRTNKbReuhyszpKHukfpH+5chYvWP7E hhblg4JhANcym4xw/9tzRGCoCpRkGNwZdDRldTY0pVdo1dSY2R8DbEFClZqbOX1JRi3XPPqW20h FfABkzgevGFS7Nd6NwdIN9m06Y+Ba3rl2fMub52dOoIhos9WiJgLyjAEwYjt64l4VdNLh/WscJp lLPWRTg3KoZ0cKpYzjsvAK8gO+KDzuV3WNckTpd8aJsqD1EjGzXQqQrdqYT+9CIeC1zmwqcszst dNfcDu9msdpx+qg3g4ZtW971iM8CvKNTuY3/sKZ5JuFMk6U886TEA06NYHMse6WjRGH8YeitgPi 5h1D5HAy62qEvHM/+9XiCXE7hX+mIZ6E2Pq9LXitgQJ/0U= X-Received: by 2002:a05:600c:6305:b0:495:6396:8b67 with SMTP id 5b1f17b1804b1-4997c0d7658mr46953065e9.4.1786533517220; Wed, 12 Aug 2026 04:18:37 -0700 (PDT) Received: from fedora ([202.47.63.86]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48150d702c9sm6670072f8f.34.2026.08.12.04.18.34 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 12 Aug 2026 04:18:36 -0700 (PDT) From: Muhammad Bilal To: platform-driver-x86@vger.kernel.org Cc: jorge.lopez2@hp.com, hansg@kernel.org, ilpo.jarvinen@linux.intel.com, linux@weissschuh.net, linux-kernel@vger.kernel.org, stable@vger.kernel.org, Muhammad Bilal Subject: [PATCH v2 1/9] platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer Date: Wed, 12 Aug 2026 16:18:21 +0500 Message-ID: <20260812111829.172273-2-meatuni001@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260812111829.172273-1-meatuni001@gmail.com> References: <20260812111829.172273-1-meatuni001@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" hp_get_string_from_buffer() clamps the converted string length against the destination buffer size with "size > dst_size", so when the converted length is exactly equal to dst_size, conv_dst_size is left at dst_size and the unconditional NUL terminator write dst[conv_dst_size] =3D 0; lands one byte past the destination buffer. This is the same shape of bug as the previously fixed off-by-one in hp_convert_hexstr_to_str(): the buffer is sized correctly for the content, but the terminator write is never checked against that size. Fix by changing the comparison to ">=3D" so conv_dst_size is always left with room for the terminator. All fixed-size destinations that reach this function (path[512], current_value[512], current_password/current_value[64], and the per-entry buffers in encodings[][512] and prerequisites[][512]) are affected. Fixes: a34fc329b189 ("platform/x86: hp-bioscfg: bioscfg") Cc: stable@vger.kernel.org Signed-off-by: Muhammad Bilal --- drivers/platform/x86/hp/hp-bioscfg/bioscfg.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/platform/x86/hp/hp-bioscfg/bioscfg.c b/drivers/platfor= m/x86/hp/hp-bioscfg/bioscfg.c index 2bf57e6eade4..0edc6e7cfa9a 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/bioscfg.c +++ b/drivers/platform/x86/hp/hp-bioscfg/bioscfg.c @@ -85,7 +85,7 @@ int hp_get_string_from_buffer(u8 **buffer, u32 *buffer_si= ze, char *dst, u32 dst_ * bytes. */ conv_dst_size =3D size; - if (size > dst_size) + if (size >=3D dst_size) conv_dst_size =3D dst_size - 1; =20 /* --=20 2.55.0 From nobody Tue Sep 29 04:39:33 2026 Received: from mail-wr1-f42.google.com (mail-wr1-f42.google.com [209.85.221.42]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E2FBC4334C3 for ; Wed, 12 Aug 2026 11:18:41 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.42 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786533524; cv=none; b=V7JqsNfYBxe9Sfm9ju1rDgmO2GXTozWfGBolyCrwtzRH79o2e0g2uPyQ3DjTlcVie4nmxnsG9jYSgRnZngVQ8RfqR3Jzg5jDutdH/6HQgHa3zU/hs4PPrgrhKbNw8zbttPuMe/w/lXRT7vul/vWTZNDP9zleL0UfZ/vho9FLF8o= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786533524; c=relaxed/simple; bh=GXnVaGcOYcGeGF51vfhkksxSxm5iT6MduRJD27H8KxI=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=nz2UImnGbVoyIV7E09yj//vWj12OgcvWAkW7tLR43bh+DaOG6t8uuMyWYZUUOm46fU9xnU0P5jJal8Txq50NPKn2h3G9Capu/1XUH8dfTmqH27/nJ/1N/y/SR3rLju2Okt/vyxvEmVeu4jIbdUvqpguuPQEBHg+EcxVwxZuSQm8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=NBLpEhoH; arc=none smtp.client-ip=209.85.221.42 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="NBLpEhoH" Received: by mail-wr1-f42.google.com with SMTP id ffacd0b85a97d-47f93b2fe4cso450054f8f.0 for ; Wed, 12 Aug 2026 04:18:41 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786533520; x=1787138320; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=jRznYyon0XGUdVgbipyEvsqHsHiyM4eqeCRczfbwZQQ=; b=NBLpEhoHisei3vTNn620D1jR8HVSu9eBlNFN5zSLwKEICdz1JIF+tsgwOr9ueDu3c0 D2rTx7iFOFnWn8HqO4aendeFaiZ3QAX/Gw+lhmrVDHH653d8lpTCTpn2KZwpwoZAaSuj MknykyhSrcllnMxRCgzQbYR8EJoDHLB93eBCNe8p7HmfiPeJDll90CHlAoUSwHObS+zM BN02A6ffudM+7YKi510eVnBM/2UXM49cQzBZP0WFIGcEw3++xzvIGuYCD0tn4FAj+0of tGYFoI8c0yDbqZo7eTohHw++CzZBGEbiRPGzkV1j9rIuLjcK9in+H3hji83bNORDVZVU IZWw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786533520; x=1787138320; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=jRznYyon0XGUdVgbipyEvsqHsHiyM4eqeCRczfbwZQQ=; b=PG0PYm6e+4Bzm5vDc1yOuntERmnJ7rH7ZmzTmK51AZAr98HJrkAwaS1Q9YI7Aer9fB yGsK466cWCCFwktqLcQybDeqozG3RmMbtehabZ2ag7xjqamdfWamOCExToxiD5TIlEuX X42650hqLrXMd9kr40Qv3yBkCD6dR6klMrGsMXZHVLkg3Sr3EBIb9jDYCoUlzO9UcDmc 0TNm4gaqcibOGYrGIIbUBJvU3bW/wFMGcU/GYZltKla8gUp3BMpT5ej7ZG54Tc9MRtxm eXnwgPDJrJyGprNuSrq5OhG7rSaNL/tU4n0v+2Q0z2F2MzGhe08vyZfFJGfwax4+EKaM 6F0w== X-Forwarded-Encrypted: i=1; AHgh+RpkMLCdrlnbt7BLqe6HG2HttrS+qA4CbF1cW5Xfjwj05sPRvB2Atpv5cBJU1tcj20MJeUnjB6ZnNrJIsNM=@vger.kernel.org X-Gm-Message-State: AOJu0YySC8WObq55FSgW3Y9Z8yqpYgw1gBZhL4nOeg/1TFY3Bygl1Vie BYITjiRSOl5pH/AVw1FfWbQig8+B/5AR7m1r+o0WZfezjj1fEPLh87up X-Gm-Gg: AR+sD1355F579GUMLYTmyXJqFg+5zZhqNtpewdGPxGT4lzbPHrM60Y3S/Ush8ShwIL/ K740YSBpYFAilEh0/my5zS9estSz6mJgMDwR/nCpMyn/wab/opD+hbzXPHMPFUsyT+kpMRadNxY a4Y19rRq5JumXgLSnWRQd9LPNna3v1syz3V/nhzHmFzEEJrNhW/qjUymYmUuUCEDXLKNXUXL2UN 4I1ISM1oP/s8XlLoS7anyadpF0UB2PPlcOzYpJukOXtF3BLU4ESAvQ+okNRg9dgwdwe3ImKjARs K4UuR4d2Ed3+wPbVX7cUd8Z2davmSq9xjZ8YkbfTwBb1rVq7AvbJuIi91/A6GZquY8t1KzrlKHk yJ9ho1Dd0Sl2XjMUBc2BD5LyUCnACgWtRvhh0yXGAWcSaiKjZCyYa1Yuf5CM+F9/iSRMFkcJ8x2 jiJGaR2b1hyt2y7pIEOJAWMbNRirwzOIZotxK/W8pGN34KvJaCDsWkTbXpE2G4Bp0Ej1hrxu6zO LKw4Gl9SQcpwSGydhrPaH1bdftu4rAZo6ZaYlbNJw== X-Received: by 2002:a05:6000:470b:b0:481:5657:5299 with SMTP id ffacd0b85a97d-481565752a7mr2352055f8f.0.1786533519885; Wed, 12 Aug 2026 04:18:39 -0700 (PDT) Received: from fedora ([202.47.63.86]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48150d702c9sm6670072f8f.34.2026.08.12.04.18.37 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 12 Aug 2026 04:18:39 -0700 (PDT) From: Muhammad Bilal To: platform-driver-x86@vger.kernel.org Cc: jorge.lopez2@hp.com, hansg@kernel.org, ilpo.jarvinen@linux.intel.com, linux@weissschuh.net, linux-kernel@vger.kernel.org, stable@vger.kernel.org, Muhammad Bilal Subject: [PATCH v2 2/9] platform/x86: hp-bioscfg: fix heap OOB read in sk_store and kek_store Date: Wed, 12 Aug 2026 16:18:22 +0500 Message-ID: <20260812111829.172273-3-meatuni001@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260812111829.172273-1-meatuni001@gmail.com> References: <20260812111829.172273-1-meatuni001@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" sk_store() and kek_store() strip a trailing newline from the sysfs write before allocating the key buffer: length =3D count; if (buf[length - 1] =3D=3D '\n') length--; bioscfg_drv.spm_data.signing_key =3D kmemdup(buf, length, GFP_KERNEL); but then pass the original "count" (not "length") as the copy size to hp_wmi_perform_query(), which memcpy()s that many bytes out of the "length"-sized allocation, reading one byte past it whenever the write ends in a newline, the normal case for a shell "echo" into sysfs. KASAN confirms this directly: BUG: KASAN: slab-out-of-bounds in hp_wmi_perform_query+0x1e9/0x460 [hp_bi= oscfg] Read of size 28 at addr ffff88813c8e2b80 by task python3/16022 ... sk_store+0xa7/0x240 [hp_bioscfg] kernfs_fop_write_iter+0x3e1/0x5d0 ... The buggy address is located 0 bytes inside of allocated 27-byte region [ffff88813c8e2b80, ffff88813c8e2b9b) Reproduced identically for kek_store, and at multiple write sizes (28, 57, 201 bytes), each time reading exactly one byte past a kmemdup() allocation one byte smaller than the write. Fix by passing "length" instead of "count" to hp_wmi_perform_query() in both functions. Fixes: b2715aa2e135 ("platform/x86: hp-bioscfg: spmobj-attributes") Cc: stable@vger.kernel.org Signed-off-by: Muhammad Bilal --- drivers/platform/x86/hp/hp-bioscfg/spmobj-attributes.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/drivers/platform/x86/hp/hp-bioscfg/spmobj-attributes.c b/drive= rs/platform/x86/hp/hp-bioscfg/spmobj-attributes.c index 2b00a14792e9..4d94e48c1a4c 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/spmobj-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/spmobj-attributes.c @@ -238,7 +238,7 @@ static ssize_t sk_store(struct kobject *kobj, ret =3D hp_wmi_perform_query(HPWMI_SECUREPLATFORM_SET_SK, HPWMI_SECUREPLATFORM, (void *)bioscfg_drv.spm_data.signing_key, - count, 0); + length, 0); =20 if (!ret) { bioscfg_drv.spm_data.mechanism =3D SIGNING_KEY; @@ -274,7 +274,7 @@ static ssize_t kek_store(struct kobject *kobj, ret =3D hp_wmi_perform_query(HPWMI_SECUREPLATFORM_SET_KEK, HPWMI_SECUREPLATFORM, (void *)bioscfg_drv.spm_data.endorsement_key, - count, 0); + length, 0); =20 if (!ret) { bioscfg_drv.spm_data.mechanism =3D ENDORSEMENT_KEY; --=20 2.55.0 From nobody Tue Sep 29 04:39:33 2026 Received: from mail-wr1-f52.google.com (mail-wr1-f52.google.com [209.85.221.52]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A61ED4334C7 for ; Wed, 12 Aug 2026 11:18:44 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.52 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786533528; cv=none; b=PBPuhRW3iN8U0j+NhACbph4mee2AVzYN9bW7aq1XfUvZXtJk5ag1n9n5XpMJiohrkEVzUpcR1dWnldDXTqoTdwS5qcUTmy9uZ0xdslJripYoy4Hx6bwCeZH5bt+xN/5YXTGA39gNeeMIUS5iHefAktoHdnfWw6kurYSV3BNYTpw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786533528; c=relaxed/simple; bh=r6Cbjl4OVGNVNoYln0kbEziovWGUtHxY0z02La/a0yE=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=gZ+YBPiLVXsKkJCFbo20T9/P3+zuxahx/m8EbRrBkyFfLFyXek7ByeK8uMN6mC5PP+1n6H0cpmuadwKWuDzY+hd1FZ36HQFQE3yWoEZ50Y5RI6a7rXwCqR7TFAGNtg6jfvTBuMzH3mF66kPMet+uhEuRwiQFSPvZTcI3Sf1wJrg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=UzbaZC71; arc=none smtp.client-ip=209.85.221.52 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="UzbaZC71" Received: by mail-wr1-f52.google.com with SMTP id ffacd0b85a97d-47f703a9e5dso388125f8f.0 for ; Wed, 12 Aug 2026 04:18:44 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786533522; x=1787138322; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=PdRDhdZcnRfVrf9wRzs0djvfPZrw61+L7S7NLduJJu4=; b=UzbaZC71OTzWsdFtBndbCNf8UETNfC/ScfpZqz/Z0qKGPrAqzPGw7gO8LnVLyHnqiW 5pYRqLghuVmA8xy9oGb6Z8F/s1cjyej5Zy1UaLmbt1PcHGXAf12QYO2CKQExxqjjffTA H7eO/dhrZZAozvNdbvrOLlJlTMouVUvhg9v54yQXG6wVWXmRlLRrMRMhrYOKvERi8q/l Op9s2WtGXhjRmeZgSHMti/JyrECACdHsYuaATrnDr21OBr1tAI/Kbxdrx3S4NA7UwVPm fl3PJ9AVRqUvd8XZ31FNkzrEcfmKqIB/6JYjEIyaaTzOAkxxKJaDQV0p/ix93xYm3HYx JGyw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786533522; x=1787138322; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=PdRDhdZcnRfVrf9wRzs0djvfPZrw61+L7S7NLduJJu4=; b=K8LT0xz6/2GNNQWfgMp7HvISmqDEeu2vPvHSRy5w8v622CizE6ox22M/E0q2HhMgpV bj1uDLJzSnw7pfpyBBcq7RMIVJ3k4sejonppz3Sy0BZbiZOHOeFcSrwkyUD58gJkGl48 gIlz80uo8sXBiYdEgSKb4YSrqYhXzxa3jOg1s3sGhZ2/knLlwzhWn1d8jiHbDQEVr4N2 R6h1/h6HMTPHY5Xpr363xkLNnVwaTen7KfJUOaKDlH/IuxCKsD/0JsCTV1C0DkyyEUzl QxRFPt2IbARM1J27JQBsv+hlNleLIKjm0x8FlTHh11+BxYTN08ugNEc6UhW/OpyAtNMR wjRA== X-Forwarded-Encrypted: i=1; AHgh+RrAASfYiXyM8lqyybXgGuwmLOQx9NNevq4VECuc742ZYbWatUXbMJB2UkbtJRf1WqQCTUi7KcIqGERRR2Q=@vger.kernel.org X-Gm-Message-State: AOJu0YyfEpNiGPlRrv0BBZOUSfXOIR/1I747D3mED4IMKuT/n3IyIBNQ XQAdryYYTv4fNrAaY9KhSsxkaV1hkm8L+W3O8ge9UQloDKiLz+vYXQEl X-Gm-Gg: AR+sD105crYhbG7b4S1csiJBn3lOSyoylf/0XfvS2865kNIhU3CmWYGnfw9GrxLb57R g2n/oq0QfJjNYZ/4ZmmIpRHeLrRat6Z4x9yPglLJx97wIKeS94HJD290GIFdq3kXv3t7sHEA4/j K9ssOQmm+KuBvRaCPAx8qL7ZZkLwkVZCCPmUFTgX4PV1fyGTsRmSyFqvCM5a/pIHC2q0NnAcueS /wC9dHGptgKdaFpD7atCz+w1lNhGnqCBAq/1p04uRglqg3MPAiB0gqq24j2VJLwEN7Ir0VQ9Z1a ilmYJ24Dw8Y24yYHIQMW7U8N9JKiN9klyeKotIoP0TUA2j786s9OsINzOijpyXc8H1BClE2fY/o +wYra/TH3aHFnBrwuYMUI+7qR/61nKRrLb6kkVkvZQTDd87NYK/QkeVErel+2qPpvH70aiZH1kS dMw6KdqZ7y6v8wT3ZCz5Vr19Gec1U0n5W0xm+1w2xJt+WFadFo2mtsS68ivkWmkDznXtRn5vAdh K+mNTK1cAC0R+fHgfZYR0IVrnPHSChlHbxRWJdMOA== X-Received: by 2002:a05:6000:982:b0:47e:9f16:c0bf with SMTP id ffacd0b85a97d-48152c892c8mr5968232f8f.30.1786533522478; Wed, 12 Aug 2026 04:18:42 -0700 (PDT) Received: from fedora ([202.47.63.86]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48150d702c9sm6670072f8f.34.2026.08.12.04.18.40 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 12 Aug 2026 04:18:42 -0700 (PDT) From: Muhammad Bilal To: platform-driver-x86@vger.kernel.org Cc: jorge.lopez2@hp.com, hansg@kernel.org, ilpo.jarvinen@linux.intel.com, linux@weissschuh.net, linux-kernel@vger.kernel.org, stable@vger.kernel.org, Muhammad Bilal Subject: [PATCH v2 3/9] platform/x86: hp-bioscfg: fix heap OOB read on empty password write Date: Wed, 12 Aug 2026 16:18:23 +0500 Message-ID: <20260812111829.172273-4-meatuni001@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260812111829.172273-1-meatuni001@gmail.com> References: <20260812111829.172273-1-meatuni001@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" validate_password_input() computes length =3D strlen(buf) and then checks buf[length - 1] to strip a trailing newline, without checking that length is nonzero first. Writing an empty string (a bare '\n') to current_password or new_password gives length =3D=3D 0, and buf[length - 1] reads buf[-1], one byte before the heap allocation holding the copied input. KASAN confirms this directly: BUG: KASAN: slab-out-of-bounds in store_password_instance.constprop.0+0x2= 23/0x2a0 [hp_bioscfg] Read of size 1 at addr ffff88811bd8da9f by task sh/13740 ... store_password_instance.constprop.0+0x223/0x2a0 [hp_bioscfg] current_password_store+0x14/0x20 [hp_bioscfg] ... The buggy address is located 23 bytes to the right of allocated 8-byte region [ffff88811bd8da80, ffff88811bd8da88) Reproduced identically via new_password_store. Execution continues past the bad read (the garbage byte only affects whether "length" is decremented by one), so the write completes and returns success; this is a pure information read past the buffer, not a crash, but it is still an out-of-bounds access KASAN correctly flags. Fix by only checking buf[length - 1] when length is nonzero. Fixes: 8646a3b5ee3a ("platform/x86: hp-bioscfg: passwdobj-attributes") Cc: stable@vger.kernel.org Signed-off-by: Muhammad Bilal --- drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c b/dr= ivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c index 4d79eb8056a5..86fa03a5ee9a 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c @@ -66,7 +66,7 @@ static int validate_password_input(int instance_id, const= char *buf) struct password_data *password_data =3D &bioscfg_drv.password_data[instan= ce_id]; =20 length =3D strlen(buf); - if (buf[length - 1] =3D=3D '\n') + if (length > 0 && buf[length - 1] =3D=3D '\n') length--; =20 if (length > MAX_PASSWD_SIZE) --=20 2.55.0 From nobody Tue Sep 29 04:39:33 2026 Received: from mail-wr1-f42.google.com (mail-wr1-f42.google.com [209.85.221.42]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id F070A435AAA for ; Wed, 12 Aug 2026 11:18:46 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.42 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786533529; cv=none; b=cvaUj12lWr+SsINo1uyiobS7Ila73AX4mUow2ATvxbtpqdkUr8Z28zmq82gq3fiXh7UrRphcN+lbKnOF2DYOQQiJA0KZRAaci5tE0P6ezC8ALsqNJmZSCn05sISC5o4xtd81oT6lqx5ibxh4F3z7kwCvndmD5qBG197MltA0sBY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786533529; c=relaxed/simple; bh=ATKvWl1DnIWOGmblRvXvDZPEp2qoEl7qqfbdLw7wl3E=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=egzDvCflUzwl3YJoTVd8Q9JjXhSnXKtcm/vzs315e8rVzJDZVplmsEZAzk+HesKBUMQojTX4cyJsBzth71SNOu79xVYB/MkShG+glabr/q6TrV4bYM+7UQVHbXDhBVsJ5Dxr1rR5RpRiUcFoo8ilmZ35XVeexYdmlo1DIwCtAJA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=UPoC98/8; arc=none smtp.client-ip=209.85.221.42 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="UPoC98/8" Received: by mail-wr1-f42.google.com with SMTP id ffacd0b85a97d-4798bea72f9so404458f8f.1 for ; Wed, 12 Aug 2026 04:18:46 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786533525; x=1787138325; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=GsPuPtlEtpcGKckM/9mBE7kyPjRyXeXRo57w8zpUvug=; b=UPoC98/8UNWIKkpjNwtvUiOxBBvc4dwZSjOxGo02t+ZvsUrufig+2dJGuYtqljphic LwpkDLlXJIZTnlPwuA7MnKUm/+ZCbZw7XcSwlkqCqEEeVZHp/o2LDXqtqTXAfd2eauYj IZw8UCvL0oF+Qa1rNY9DYvxqnuZXQIjocG2Bz2Rs3tfFKyGHMO4KQjwU7AZOxERacwHn zwB9D16yxn7sfDybvIgNZXPL5UWgafQfBJOJlgW0CiMxK9+8VChVO2sOkiv4AhP4DlUx 0JEBThkNVcmkk6OpTawx0RQ/J19ccdm7tw6Sde/gHojH1BAnDTK+3A504aDg2Lmcm1ct D26Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786533525; x=1787138325; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=GsPuPtlEtpcGKckM/9mBE7kyPjRyXeXRo57w8zpUvug=; b=T+4NmvcQBNuPcngqM3gL5ANxxG1o8DYCCrYcsH/xEu3ULGt1iZn0L9zyRi6+D+O1Yf HuK0NYsovGSyQ34758eJWZARV3JTwErDYhY3ime84eARp9g63mtEHiTelPT8iShpNZYo teiqllrAcNYuRm1rs5lrX/q+Meh91v792sSPHQ3dLv4IzRur34138s7n7yIY7Ry2ePGg x8MMCvo9ECIBjjUPuWOL5+4kISG21+W0rKrAgrMqOIAOsPNO93SD9ppmULQNp88FHGDO qLHmO81i/7wFndB8c0XhED+dd+zy1RjoWbivlXelccHvdSEkIIqdiBs3RMpiIYoIuaSS rJag== X-Forwarded-Encrypted: i=1; AHgh+Rr9nuOtPajSTABcwljuj+yAiVtIUZbazzOxrPdoLXQcaXl7qvxncHuKpLpfTDsf2U5vV2O1oMHDjhrzYwk=@vger.kernel.org X-Gm-Message-State: AOJu0Yw+0LDDFhDXDv+tgVBudZ3D3BoNWZyaBWT3Wph42WCyOCEXwDyl aZDjVKvVcMnt/6b3qyAxeCu6P+N7JWhEM02Z/A0KtAnR92p3T1RwGWnt X-Gm-Gg: AR+sD10fxHxfavJwP9Bd8vtmKZkkDsxhea+11mc63GGW79EHUnsIFmsgnh6NrysiTsZ gILLyOw1WZl5wcNp0Wf4PsfnmmoNH2mcBU8gAbOssUBZXuQGBlfJJ4BbUgOla345AZLCT+oeLHP 8irhKuFTBS7b9Okjsa3nDs9lUWsuNk5VvQa7MYjx2oijINb5GqJTUVEXlZXIX9faHGC37QRE/Zr A8iaxfIckBPmBsaHaX4kLv3FJZpbq6Dx5WgJtgqD34RHisljumRFzYGCUjPU9KZgDoRZcoB2lWA 7+BbxpS7n4IYWbzEsAEDhWFQxOUNM3zK5JHi6cGjlQ14WTQDrdQ+OzIKALSvDwv6geTgfhWKfiK 748VxCVOlpAua41tzsNfhtUMxqkJb57WoqzF9aWdoAKGAyiWhA3g4dsKB1414Ta7gPBipMFXcu4 aZvo3duQj9ecd9bpG9KDMC8VfoU1C3RX0bzqBaTteYrVrPY4/NVqQ19aGyreh1qOzvR+0OZjqyk leAyQ/HnQOPJr5xzCp5Xsf5bzze8L6yexQ+2IW6Yg== X-Received: by 2002:a05:6000:2a89:b0:47f:e729:c588 with SMTP id ffacd0b85a97d-481528d77cbmr4832014f8f.14.1786533524857; Wed, 12 Aug 2026 04:18:44 -0700 (PDT) Received: from fedora ([202.47.63.86]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48150d702c9sm6670072f8f.34.2026.08.12.04.18.42 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 12 Aug 2026 04:18:44 -0700 (PDT) From: Muhammad Bilal To: platform-driver-x86@vger.kernel.org Cc: jorge.lopez2@hp.com, hansg@kernel.org, ilpo.jarvinen@linux.intel.com, linux@weissschuh.net, linux-kernel@vger.kernel.org, stable@vger.kernel.org, Muhammad Bilal Subject: [PATCH v2 4/9] platform/x86: hp-bioscfg: fix 16-byte heap overflow for empty auth token Date: Wed, 12 Aug 2026 16:18:24 +0500 Message-ID: <20260812111829.172273-5-meatuni001@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260812111829.172273-1-meatuni001@gmail.com> References: <20260812111829.172273-1-meatuni001@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" hp_calculate_security_buffer() special-cases an empty authentication string and returns a fixed 4 bytes (sizeof(u16) * 2). But hp_populate_security_buffer() does not special-case that same input: for any authentication string that does not start with BEAM_PREFIX, including the empty string, it always builds "UTF_PREFIX + authentication" and converts the result to UTF-16, writing a 2-byte length header plus 2 bytes per character of "" (9 characters), 20 bytes total, regardless of how long "authentication" itself is. The caller, hp_set_attribute(), sizes its kmalloc() buffer using hp_calculate_security_buffer()'s return value, so for an empty authentication token it allocates 4 bytes for the security area but hp_populate_security_buffer() then writes 20 bytes into it, a 16-byte heap buffer overflow. The authentication token used here is the current admin/setup password, which is an empty string by default until one is configured. Any write to a writable BIOS attribute while no admin password has been set reaches this path. Fix by removing the special-case short return for an empty string in hp_calculate_security_buffer() and letting the normal formula run, which already accounts for the UTF_PREFIX correctly for the non-empty case; for an empty string this naturally yields the same 20 bytes that hp_populate_security_buffer() writes. Fixes: b2715aa2e135 ("platform/x86: hp-bioscfg: spmobj-attributes") Cc: stable@vger.kernel.org Signed-off-by: Muhammad Bilal --- drivers/platform/x86/hp/hp-bioscfg/spmobj-attributes.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/platform/x86/hp/hp-bioscfg/spmobj-attributes.c b/drive= rs/platform/x86/hp/hp-bioscfg/spmobj-attributes.c index 4d94e48c1a4c..2d4a3720f80c 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/spmobj-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/spmobj-attributes.c @@ -48,7 +48,7 @@ size_t hp_calculate_security_buffer(const char *authentic= ation) =20 authlen =3D strlen(authentication); if (!authlen) - return sizeof(u16) * 2; + return sizeof(u16) + strlen(UTF_PREFIX) * sizeof(u16); =20 size =3D sizeof(u16) + authlen * sizeof(u16); if (!strstarts(authentication, BEAM_PREFIX)) --=20 2.55.0 From nobody Tue Sep 29 04:39:33 2026 Received: from mail-wr1-f49.google.com (mail-wr1-f49.google.com [209.85.221.49]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D3038437841 for ; Wed, 12 Aug 2026 11:18:49 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.49 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786533532; cv=none; b=Hl7bYboxcbOz1TQ2tCbFKKWE1pirUNaYsfBIXeAs3x6Zt2gNvfY/bfbg2jncMLPTmTJfjMyfrfHxgEnpyeZsEvNmm18W8vORZYThHNBrKumg7g79Ub/6TwUsbL/rnBDsALlCqOUfjauxOPhMbgWZ5pHS71wPYUTXW0vxAoci2+4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786533532; c=relaxed/simple; bh=9EehTMGdJoM/pmPAG9mZtREZbrypCyCVR7Mvq/DwalQ=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=bpMdKNBd8imTLi92m5gQBtokcFlLzkKLa4FqKxCkkHdS6KBBPWclTHX5pKiXYqT7FBwiX9jRBm6nOqvA9BEciYY2QeZVdqvwJDrPeo2tuWQG6Z8cKHZqSzvOAHao8W36jfPSmm9jo142+K96b8lXv/ILEHey9ztxLBf/X9L+fqI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=BQxHgS0H; arc=none smtp.client-ip=209.85.221.49 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="BQxHgS0H" Received: by mail-wr1-f49.google.com with SMTP id ffacd0b85a97d-47f703a9e5dso388242f8f.0 for ; Wed, 12 Aug 2026 04:18:49 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786533528; x=1787138328; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=K+s/eo+/pWpLLFnoufPaOpVfgTjc+a46l3h08Co/MXY=; b=BQxHgS0HfQtyGfRnLr5WsGMWqfVYh/WwUZwcb5pDy+K0MmzYC2/+Q2ohurf+Fg/H1Z 5fjaure2dBsBtEc/LhkKSn2ZddCIoLxySDiIMLWhCpIGUJKBIUa11JAeO4rbQzfDHAXx JQ8JxDlVrPGX6AkbILVgLHrOD6M5HNFMfMGz1vVl7Ivk7opbz3C9UC9b8TSBIeJHzUtt SXLJNgiBsHCHJKJEHXlmRCRbd9bQ3Y+i7H5XKGtdnuw018/Kvs6EgOa9VS584/09TcD8 ul5527RaeAYj6Sx3L5azq5ZwuAbvRM3cr7hQTjyf/pLmN3B+D/0yptVOmE+1FGvdtYm+ tJAg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786533528; x=1787138328; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=K+s/eo+/pWpLLFnoufPaOpVfgTjc+a46l3h08Co/MXY=; b=MjNww64U2ZI03tkXiZUg+Yka8sixMdx2OgleQgrNS9eD0OsogzKmfKmqPTigP7+e2J t8+qhtO2YjICJ2RmmMfn8k914VNnpsroL2Ptr+DsUZYNxTwHF8EbXq/EHi+kp5ID9XJA 8ghUVx5ASCTDuKolIFT7faWRfs/Y6qngQlP22b4iLx91Ihf9lrFlR87UGtsB/okbtDNK h58iwNiiXKrNBVLuvwCmbe38u+2mqc3U8MkqUQVHAOpI+pMR58GWm0M8/r71OZvZfdjX TCUqOW6DHsIWWT4H4/p5Hz2rMnaHsmMnLgSC/KZK7mXVfhZcrrc+AyOz/jxIdJVaf6Zl titw== X-Forwarded-Encrypted: i=1; AHgh+RopuvjbdV0YSz7ysB5o5nsQXuLV4dyjj6mTG3/8VKlnpMabnmiiSx0k5DdYGj9vXyyyV9NdFQ0p1xxD/g0=@vger.kernel.org X-Gm-Message-State: AOJu0YzESR9el3oEA6OgbJxaYrU1e1yVlzASdbfaCfJP4GThLa/EbLmc wK7vVnhq9q7yFf7EQRfS8DXh+2dbLzyc1COgfy+t5vVtXvT4xsOWjPxZ X-Gm-Gg: AR+sD13R20ThPoCKow/1tmlDePJwd6YN3LDyHlj4WMWQwv/2x+/XnCedEr+xmdoftfw jz3o/gQeKbmkI1aYaMY+zzNQn1xp1urLRSntmAKt3Bp+nqMhzmzaCJu9wjfPgEK1kEgzVtMUdbA 66FhmWnMGBkM+WF6mCbM46vgKBITJLN7pNhaH3DicYF5dJ0uQrTqKlK54kcLx3ZtPhO4Y+cRc8B yvNobzpwKm+DWcRb7Qj/LNui2QbKaHfdy/sdI7e5Sb+nhIOeXoSMjiDEBE/RP3J8iuxr5uEhzE+ 0NxK/cKSBu3QjZ17O0SVlQeis8rC0OGdvMCA+vTY5yXPSJ3vXLAB8amYWbQUVg3Fdfjj8HcuSDn fYSuo9C9x3Mdidm6POxI5aJLg8OdDqQ8TSTEBCCDqHAtDAwEA88Sb27j8WwKJ4e8agw9qQSHzg4 cOVdiSU++x1VA0y98wv9eSQyX2eC82Fz53MUOuFnL5L03m98x3geY40uuL5FcON+nS/K5moPF8L laSJ6BVNJi/De6qBfGxvyvzJkwnsjXQZYWxTUWdxQ== X-Received: by 2002:a05:6000:606:b0:47f:9aef:5515 with SMTP id ffacd0b85a97d-48152b21141mr6004264f8f.13.1786533527613; Wed, 12 Aug 2026 04:18:47 -0700 (PDT) Received: from fedora ([202.47.63.86]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48150d702c9sm6670072f8f.34.2026.08.12.04.18.45 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 12 Aug 2026 04:18:47 -0700 (PDT) From: Muhammad Bilal To: platform-driver-x86@vger.kernel.org Cc: jorge.lopez2@hp.com, hansg@kernel.org, ilpo.jarvinen@linux.intel.com, linux@weissschuh.net, linux-kernel@vger.kernel.org, stable@vger.kernel.org, Muhammad Bilal Subject: [PATCH v2 5/9] platform/x86: hp-bioscfg: fix off-by-one heap OOB write in audit_log_entries_show Date: Wed, 12 Aug 2026 16:18:25 +0500 Message-ID: <20260812111829.172273-6-meatuni001@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260812111829.172273-1-meatuni001@gmail.com> References: <20260812111829.172273-1-meatuni001@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The per-iteration guard in audit_log_entries_show() is: if (ret < 0 || (LOG_ENTRY_SIZE * i) > PAGE_SIZE) break; ... memcpy(buf, audit_log_buffer, LOG_ENTRY_SIZE); buf +=3D LOG_ENTRY_SIZE; At i =3D=3D 256 (PAGE_SIZE / LOG_ENTRY_SIZE), LOG_ENTRY_SIZE * i equals PAGE_SIZE exactly, which is not ">" PAGE_SIZE, so the loop does not break and instead writes another LOG_ENTRY_SIZE (16) bytes starting at offset 4096 of the page-sized sysfs output buffer, one entry past its end. This needs the BIOS to report more than 256 audit log entries, which already exceeds this driver's own documented LOG_MAX_ENTRIES of 254, so it requires a non-compliant or corrupted firmware value rather than the roughly 85 million entries an unrelated integer-overflow read of this code might suggest. Fix by checking the bound against the offset the write is about to reach, (i + 1), instead of the offset already written. Fixes: 63e8f906e94e ("platform/x86: hp-bioscfg: surestart-attributes") Cc: stable@vger.kernel.org Signed-off-by: Muhammad Bilal --- drivers/platform/x86/hp/hp-bioscfg/surestart-attributes.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/platform/x86/hp/hp-bioscfg/surestart-attributes.c b/dr= ivers/platform/x86/hp/hp-bioscfg/surestart-attributes.c index b57e42f29282..6b63fdb84606 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/surestart-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/surestart-attributes.c @@ -90,7 +90,7 @@ static ssize_t audit_log_entries_show(struct kobject *kob= j, HPWMI_SURESTART, audit_log_buffer, 1, 128); =20 - if (ret < 0 || (LOG_ENTRY_SIZE * i) > PAGE_SIZE) { + if (ret < 0 || (LOG_ENTRY_SIZE * (i + 1)) > PAGE_SIZE) { /* * Encountered a failure while reading * individual logs. Only a partial list of --=20 2.55.0 From nobody Tue Sep 29 04:39:33 2026 Received: from mail-wm1-f44.google.com (mail-wm1-f44.google.com [209.85.128.44]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7339D4398E4 for ; Wed, 12 Aug 2026 11:18:52 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.44 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786533534; cv=none; b=uqEbTLAlK5fiuwtKPe4ynbQs4CR95CtQNiGsD5gRaOP98puKcb91fGU2/SXbcB0ecFND/B60a3rwrrMu7d/9LsAw8crlMXqOhRc3dsE4mf46BxH/TFUNKIyNY3FhPDzHamFyEyI3g7SbW/nPiQON+DXrCrZk6eO4R9Mvtbynfk0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786533534; c=relaxed/simple; bh=rhV+qOT/cedymAeQ3DQaL+LQcUHG8piPrtIkVunzAvs=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=ftQdmucm9nvyw+G7sXY2u/TuObnpPc1g1a/ndlbpTwtXff7WlUDxUk23N2crJWYi3ZGRy5RBLLi3Lm0oWRZgkdg2rFFmmNaNGrcrcCjtMu1bu9n5XO4xG0YDqimWUnM/a75fc6tg8Wqt+XqoUM1Zx+sSzhirt6BGkgAySuwbkUs= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=El+bs9Sm; arc=none smtp.client-ip=209.85.128.44 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="El+bs9Sm" Received: by mail-wm1-f44.google.com with SMTP id 5b1f17b1804b1-49800c6a846so8259015e9.3 for ; Wed, 12 Aug 2026 04:18:52 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786533530; x=1787138330; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=hNoDrCXm49lLgm2lL6InxDz3MAxyPtaZVFbbdYtrWx4=; b=El+bs9SmlR5VflEY64GBmIIQXIbymJJyrUbkoKgDXdttek2k9NrNJ5kx/71CgaEPR6 zssv7Isd40wJNSNdFUzyZ8paFQuvU92g0xbLSrzWkLbQXXAgDwLMdUrouGCms1ZYbbUC 9vyId+qBqtrq4oyWvlZxNL1dXWW+mZSOOJZ7A7GozfrPKNwW34OD1t517kqocku3bz3Y 6gvIrWQscbjKJGXINXkx0GwprlqNZOpl5+s7hTX9XK/tuvMWx438UzC1H0DJG8R+TSOO FtPCAkP99Y1MULZ0AW/kezwl+VPKSQrAxfgG+sVlIUsyjZe9pv9XAQn/ms6f1xy8nz9C t0Hg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786533530; x=1787138330; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=hNoDrCXm49lLgm2lL6InxDz3MAxyPtaZVFbbdYtrWx4=; b=tRZfk/TZiWdru4Sx0mbAt1uzbd87r/R1DqZgPiILA+hfjeG5c55/YvXXX0WT/QIti8 lQ4Vs6hU4BLLiHDOgDunHAVayAH+GXRSdsI479s1AS45mNLMWymiWksN1V5i9EZx2gLR tvLm7/xyJkAd8viajJCM+x8bU0nUaFG6J4QuosKiTGb1I7QAf3OtSwNUFajU1tggC9Pf wJAOCD094uk7wHJzyP7YplfZfqGO/9QGg1577I929LEiA1NtPHpa3FcaTIo29+JnxwoD uFnguoXN3WroAP2SL+v8OJhYTnLnFUriOpfapWCpb2MdG3Odw3dz/dGGBxVx2fv28m7J gMGA== X-Forwarded-Encrypted: i=1; AHgh+RonCOtq29kYTVrAdGRqyECFqAAISPBN8EE0Zpjc7z3nJ9sxuESWfdzrURXf8VCWa7a43yPbm7NthlbxNnQ=@vger.kernel.org X-Gm-Message-State: AOJu0YwwV7d4QJqGA7GoVxi8K+RB987gvj1q1rOMqs0Lkl3uvO9Xb0FY nhZPTr94+PZI/dQ1Rc1SCV1oxMlbGPgPKuhnV5Z5IkYDK/9uLzRrCtfL X-Gm-Gg: AR+sD13W39WvWgY+YMxyZh9C/1C84/c1x+4+fFlxqbg2eCvqNFkCseFYYG+Pn4u9tC6 c/iTDgfkR4QUmiJV3Ua4/PlBCStvCMRHmZhnkksPl4aN2soRkTzQy4drR9ih/cOy6saZwz6INT/ 1Qp+/6lPJV8t/0oERFR41vvojSSjp6+ooNmLg/2wga3jPzNsvnpsFy76Uta8PF61D/VIrbET617 Wx4ROPYwz+OIBu44bx7zjkKExUviZuOFrzy4djsbvs2NRYGhcA8izLfLcZdwSl9P0vTQJzokexa RVhjiFK90+Ju2GUyZ9ELL66xfn3V3aDeV0vOYEI7EeRR94CPJl176A+R3QxV1yu8U6GXCXa99SB cc8Jq0OMXhImAK4wlImxaaS6Rw6wC/MoIOauCEAJ0SwlcDkMa1Gjc5e+EN7FSxrhezkFYyuCt/M pRHmqWoBhz9Q7oLT9qTmxrogI+/pLR/Apr6ELwV5uhw+2LRp3rXPSn+Ilw86eELUvYIMWGLNil1 fuQ8tqfuPwSVaM5uHH/8W6hnrd73is+gR/9cdXz1Q== X-Received: by 2002:a05:600c:8209:b0:496:c977:3b6d with SMTP id 5b1f17b1804b1-4997c139b0bmr62363425e9.12.1786533530450; Wed, 12 Aug 2026 04:18:50 -0700 (PDT) Received: from fedora ([202.47.63.86]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48150d702c9sm6670072f8f.34.2026.08.12.04.18.47 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 12 Aug 2026 04:18:50 -0700 (PDT) From: Muhammad Bilal To: platform-driver-x86@vger.kernel.org Cc: jorge.lopez2@hp.com, hansg@kernel.org, ilpo.jarvinen@linux.intel.com, linux@weissschuh.net, linux-kernel@vger.kernel.org, stable@vger.kernel.org, Muhammad Bilal Subject: [PATCH v2 6/9] platform/x86: hp-bioscfg: add missing bounds check in PSWD_ENCODINGS loop Date: Wed, 12 Aug 2026 16:18:26 +0500 Message-ID: <20260812111829.172273-7-meatuni001@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260812111829.172273-1-meatuni001@gmail.com> References: <20260812111829.172273-1-meatuni001@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The PREREQUISITES loop earlier in the same function checks "elem + reqs" against password_obj_count before indexing the ACPI package element array: if (elem + reqs >=3D password_obj_count) { pr_err("Error elem-objects package is too small\n"); return -EINVAL; } The PSWD_ENCODINGS loop performs the identical indexing pattern, password_obj[elem + pos_values], with no equivalent check, causing an out-of-bounds read of the package element array whenever encodings_size is larger than the number of elements actually present. Fix by adding the same bounds check, matching PREREQUISITES. Fixes: 8646a3b5ee3a ("platform/x86: hp-bioscfg: passwdobj-attributes") Cc: stable@vger.kernel.org Signed-off-by: Muhammad Bilal --- drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c b/dr= ivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c index 86fa03a5ee9a..acb123985ede 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c @@ -351,6 +351,11 @@ static int hp_populate_password_elements_from_package(= union acpi_object *passwor case PSWD_ENCODINGS: size =3D min_t(u32, password_data->encodings_size, MAX_ENCODINGS_SIZE); for (pos_values =3D 0; pos_values < size; pos_values++) { + if (elem + pos_values >=3D password_obj_count) { + pr_err("Error elem-objects package is too small\n"); + return -EINVAL; + } + ret =3D hp_convert_hexstr_to_str(password_obj[elem + pos_values].strin= g.pointer, password_obj[elem + pos_values].string.length, &str_value, &value_len); --=20 2.55.0 From nobody Tue Sep 29 04:39:33 2026 Received: from mail-wr1-f49.google.com (mail-wr1-f49.google.com [209.85.221.49]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E0AF243A80C for ; Wed, 12 Aug 2026 11:18:54 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.49 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786533536; cv=none; b=UnUYypi6QlvQxa5Fi9tZnyi9eVJq97ob1qrrr3azALcRRPLxNpSElel+NEZqcrr408otxE/q2C6xtjH4l5/yL9iGxUAL7mrVOVwa8Tv4nx+ZWcbblA/I73qkhaxiCqtFquVZupjdxdXmfPJC6yKl3C3185SUIIZgS9ncXCsa6RI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786533536; c=relaxed/simple; bh=rhIU1zG+Cz1JEJ/DZCxK23rcEZYVi7vpJbqoVBA+2qQ=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=oyW69o7BFS7m1p182FoYJiGl78+M9glWLSOcM5Iv0foiMm46poQVM0eYHR0CYgM+0LL8u1Ej/DtZiX9FtQHVHAWh6aqJvgz2YwbGjRpUZFKn6BcEMzB7FnIymIP56oZxuEcZ3L0HDUdCh8jC9718kPSEA4cJdOQTUey9chtpGZs= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=eyDDhKJQ; arc=none smtp.client-ip=209.85.221.49 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="eyDDhKJQ" Received: by mail-wr1-f49.google.com with SMTP id ffacd0b85a97d-47f92e3c14bso642543f8f.0 for ; Wed, 12 Aug 2026 04:18:54 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786533533; x=1787138333; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=TzXAlvJrvz8VJKZL5THLFAhA3g1WFYpeVuZ+6qv41B0=; b=eyDDhKJQcUn/6qaVG70x5845SB6g7ihlqCZ1k9C8xA4s08vUsk807yQ2iMtWsio3AR eyWyrgb7t4KDldnvAQbkbVKu9qRmGkn8fyAb4KLpFZFPN3VV4L+kWVJRpgedCGc3rtS1 RNwFF3phhL4r1S04kTxp3VeywprfsEVJ4QIOBUGJYt8zZtMsXQYIw+WMa1c8yXcXI/Hk CyWCvNOCnMkPfCeVphomyYmgSylyVP4OV011SyQKlB+nw038Tea1oPI6Zss8wvXxUnCb JCer5DqazN1QUHGUOAyJkS/691E3Q9hpy47cZAuQyykkXhxzJYgH5Z4Kdn23CPmAWgdI hKEQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786533533; x=1787138333; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=TzXAlvJrvz8VJKZL5THLFAhA3g1WFYpeVuZ+6qv41B0=; b=PgYr9Pq9PuNHq5U+0UjD79nNaf+682hf80T//s5s65mXQuvWQdrjFPgRMXhxrhfTOM sfvYHhWQpPwd/6sTEpCvWIPymKLSft3BSBlVMyPgezF6v99fW20+KURcu0Wwc55rzPK1 fJCDwJcP5TFdH+V9jgOkBwAPdNp4qRTdi8wx0uA7TSy4/BA9Q29YiqHi/BSIIWQvnbAV 2/FIrOJIx8hqRSbHuxRNKoecBS5Y22K07w8+Z0ai4ouGyPCK/ezkiEgjas+3FUw4tL4O IJaXfyR2bBAnyCp71tkWOfefd7pZvQlQFbgshraZWguoOd9klCrMnQ+Tx6NOC3e4jhWA D1kQ== X-Forwarded-Encrypted: i=1; AHgh+RouKGsjyzfG/eaFOIB+PazV1ymEGn0v6W0nUUqb6bhh0inz02QUvV4yajjt3Y1NbS76Pj/VyNFNhLBXySE=@vger.kernel.org X-Gm-Message-State: AOJu0YyyjN7+/w16X0IDGCUnktwSqQlnZDt4kvfQ/wfMylcEfhABTjts 9loiWkgndYkM5XLB54yBdzJBJFGcixwDB0vJBYYzEZp8GVtmZNhrB5+C X-Gm-Gg: AR+sD11MHb/pM/URMz/b1tzJKXrJyQnYmFGy5i1I/w31cj+j8+YMueZXar2q8bhtWgB 0zd0usGe7SY0y0kVKulgKgzOjLAu8BXKbH/VQ0DbNdMCZXotk8ak4yqB6pQWo9eFiiid06QdPTr o1f5otQkQIj3PTvUOcTVTLS0Yn0qpfVocd18WRmLGSoWaNL/6X25Ni8kB0OJg7IGXaNONimWQOd PM0oD44N1P7cYwS7BQRntLYI5Cv2furLckNaAN2HLPZlfgsYE78UfRW5z/NL/Z8MRW0GcV8Kgrw zvQtnbWfQN7tC+wbEf0A80UnkT4K7wmVZREwKGRJSMeWbtDnU6gjQqkeLj/K0fHbsJrkR8/sF3y IzAnxnAfyLid8QSOEx3Q/vzZnlBg/ZR1lqR7A9tmVmWG6woFSgK/+Gdl9lUh1Y5Dx7uP0FRH7hx Lolucs5VvIshaGHW3XdgFDGL3V+6m8TzT0uZsXnb3YTmBP9kyNk0xJfxkkjEniMEqOE7y8tUmYL hMKTMFjJF59AGEwpMHDABsS28/EhZvjysa7icBB4Q== X-Received: by 2002:a05:6000:490d:b0:47f:ebe3:ca31 with SMTP id ffacd0b85a97d-48152dfd065mr6373537f8f.28.1786533533075; Wed, 12 Aug 2026 04:18:53 -0700 (PDT) Received: from fedora ([202.47.63.86]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48150d702c9sm6670072f8f.34.2026.08.12.04.18.50 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 12 Aug 2026 04:18:52 -0700 (PDT) From: Muhammad Bilal To: platform-driver-x86@vger.kernel.org Cc: jorge.lopez2@hp.com, hansg@kernel.org, ilpo.jarvinen@linux.intel.com, linux@weissschuh.net, linux-kernel@vger.kernel.org, stable@vger.kernel.org, Muhammad Bilal Subject: [PATCH v2 7/9] platform/x86: hp-bioscfg: fix new_password_store overwriting current_password Date: Wed, 12 Aug 2026 16:18:27 +0500 Message-ID: <20260812111829.172273-8-meatuni001@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260812111829.172273-1-meatuni001@gmail.com> References: <20260812111829.172273-1-meatuni001@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" current_password_store() and new_password_store() both call store_password_instance() with is_current =3D true: static ssize_t new_password_store(...) { return store_password_instance(kobj, buf, count, true); } so a write to new_password is routed to current_password instead, and the new_password field is never written by either sysfs entry point. Fix by passing false from new_password_store(), matching what the is_current parameter is meant to select. Fixes: 8646a3b5ee3a ("platform/x86: hp-bioscfg: passwdobj-attributes") Cc: stable@vger.kernel.org Signed-off-by: Muhammad Bilal --- drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c b/dr= ivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c index acb123985ede..6bd56d3f5bd0 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c @@ -123,7 +123,7 @@ static ssize_t new_password_store(struct kobject *kobj, struct kobj_attribute *attr, const char *buf, size_t count) { - return store_password_instance(kobj, buf, count, true); + return store_password_instance(kobj, buf, count, false); } =20 static struct kobj_attribute password_new_password =3D __ATTR_WO(new_passw= ord); --=20 2.55.0 From nobody Tue Sep 29 04:39:33 2026 Received: from mail-wr1-f45.google.com (mail-wr1-f45.google.com [209.85.221.45]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8F6EF43BDB4 for ; Wed, 12 Aug 2026 11:18:58 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.45 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786533540; cv=none; b=X0AxG6/92CXdh/vgUBaVkIiY/tsptLpVki5RSHGS1PohzSChp7xbzni4jPjBGsHjoTSvVIk3TKjYedYljx4eHV1mU3jbTQ6sU+U3tq9fOY003R6aieDpTBBEEuM8+pEWYkWs6E1Chpps7GZmG73O6fFFObzjTUqWbqB14ylgZ0Q= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786533540; c=relaxed/simple; bh=ZqVUWs3x1BgozxV3FrsSk7Lzh34dxSnwsmeX8ZrIYuQ=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=lFaMqHpKbISiCVvbAp8o4u1XMupOnGengTeJowPkunTFwgOkLVowJ2o4CQMV7N86VgcNLG65e2Z7a2Pjtik6g+HCJa+m/c2Q926e3AIQhEB4P1e5/3bcQnTCrS2yqxh4Wv/UEqj7nqwP0e9U1QRyZnWTOfcgIAKJW42/qQ+eI7k= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=PX2VFpLg; arc=none smtp.client-ip=209.85.221.45 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="PX2VFpLg" Received: by mail-wr1-f45.google.com with SMTP id ffacd0b85a97d-47fde295992so628576f8f.0 for ; Wed, 12 Aug 2026 04:18:58 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786533537; x=1787138337; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=aGNNvpeBB2xFe8o+eAG+ITw+sBusoz0y2d8gJ/h4GCc=; b=PX2VFpLgt9rPC4lsIJ82yrS9XEqQVu+xI6CLJaQcPVxf/xvPlghy7hZ2Uk1LN2RlOT 1UmyaM0Xb4bH+QEX1LL9yReaqG6UwD9THwbSFqYhB9VV3ecyUM2j7TH24FBM+ZGhtQc+ F/Vc1UBZWvM3eAnMKR4/SZAsL9fST5KGYUyJQyaplCODubYJ/q4XiaDiP++KD1BfXqw+ mIvneW+OkI5wFnkPSV6KpD4v6aICpyV3fLONVU6apzquqQR1n8UVboqjxfn58oJgLtvH JtVcVNbiKl5hI6RwcZgn4qTBYLj1s8tbFtxgzr43kZQuT+g6c7i0HKBTh3tI+UvkE9am 0rmQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786533537; x=1787138337; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=aGNNvpeBB2xFe8o+eAG+ITw+sBusoz0y2d8gJ/h4GCc=; b=La4ng6Xi7l0ZG9R7eiMzDW2EmEkQDnuLr0Ie+PKOuuFSDCvpbQ/Y1f7JeTSGdEaYYb zW8v6/2rAvhrNgNem6/LpUtaaNxABW25ElahZlF+G9LW70OWXJiSQC4G2l1ELB98/ZbI PFN8SZ0IDgmh06aUTlS7uv4URWS29/5sRldUmppEswb2FqmqqMuocepFWo0TyHlRrk3r QHy6qqxw0ndR6gobGdZhQrFlCQRHaO65bFmm6H5CQGpbhjN5rYFzKfy5/z4rwZ6Mh04b OdPymUw7jKDckzXgAXJFzHZnF6jAVImeMzLOIvXahjOvZ8kakT7jt1hay5KdVJzH85yA OIXw== X-Forwarded-Encrypted: i=1; AHgh+RqcCkVOcphUO8TUmFHXVJR/dHUs8hxLItw6VB1rhq6f3UUFx0aPhk+SbzDlLALwf1/Aw6wT2CEOySErWGg=@vger.kernel.org X-Gm-Message-State: AOJu0YwnZJmhZ9sKs7SISClpVbqMGs7KiQgeAzRCH28sE8fvhtuZrzMe e6Z65Bh4F+gMHyZYlLHBzVVD+f97miPd3ldXH0JlPjt7eJeRicLjmEvo X-Gm-Gg: AR+sD10rWWHrzk5SaAxgIrJ5+VQxoRvMxC19aKkTM7zZzRBI84J9LoMvxmqCgb/cZFN GCl2PjPAnpr8a5BkRDloz1aP09dfqy/aLL/gdiyvhq+2Tu7W5GC8FEXr9v+9SLoRF2rALWf1Bp0 O24/NWu5FFiNyx+XoNlneviOEMnO7JDvvlsGrHA8a16puIwNj0yvxrIhgDt1P4qf02sqTgZ3vb9 8WbCTUB+49oUqhKJ4/hd8vge7yQ2Owhhc/gCvy7N6ea1pP1wPORfKJ6AG4B70TsEhC4TC73p3tc gud3reADCB1cyr/dUZm7FAiRv6ZADqDpHDyUIEMV8GTYYViLZFHpr7ydX4K7C52zMpiYHF251Gw 6k4s6y7svXHU7CTvmhkvvuGftRfFvENfR9U73fDpA03ev72Z9KSz24rpy601AVRGDJ1U+IfCQBR 6oZhfK/cywcoYmqGTzkmurXqmEFT6THB0oUrUZRmiNYlmGdBD1wdlXFxSYZ4n9fj6tAclIxyx8x LtdKSzTJVq0KNacQ/t8IbTlFTAhrtF/FyGBEn84Gg== X-Received: by 2002:a05:6000:461c:b0:47f:71a0:c060 with SMTP id ffacd0b85a97d-4814febaf04mr11662868f8f.2.1786533536719; Wed, 12 Aug 2026 04:18:56 -0700 (PDT) Received: from fedora ([202.47.63.86]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48150d702c9sm6670072f8f.34.2026.08.12.04.18.53 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 12 Aug 2026 04:18:56 -0700 (PDT) From: Muhammad Bilal To: platform-driver-x86@vger.kernel.org Cc: jorge.lopez2@hp.com, hansg@kernel.org, ilpo.jarvinen@linux.intel.com, linux@weissschuh.net, linux-kernel@vger.kernel.org, stable@vger.kernel.org, Muhammad Bilal Subject: [PATCH v2 8/9] platform/x86: hp-bioscfg: fix ORD_LIST_ELEMENTS never being parsed Date: Wed, 12 Aug 2026 16:18:28 +0500 Message-ID: <20260812111829.172273-9-meatuni001@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260812111829.172273-1-meatuni001@gmail.com> References: <20260812111829.172273-1-meatuni001@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The ACPI_TYPE_STRING case explicitly skips the string conversion for elem =3D=3D ORD_LIST_ELEMENTS: if (elem !=3D PREREQUISITES && elem !=3D ORD_LIST_ELEMENTS) { ret =3D hp_convert_hexstr_to_str(..., &str_value, &value_len); if (ret) continue; } so by the time the ORD_LIST_ELEMENTS case in the eloc switch runs, str_value is NULL (it was freed and reset to NULL at the end of the previous iteration). That case then does: ret =3D hp_convert_hexstr_to_str(str_value, value_len, &tmpstr, &tmp_len); hp_convert_hexstr_to_str() rejects a NULL input with -EINVAL, which sends this function to exit_list, and exit_list unconditionally returns 0. The net effect is that any ordered-list attribute with elements present silently ends up with an empty elements list, with no error surfaced anywhere. Fix by converting the current element directly, order_obj[elem], the same way the PREREQUISITES case already handles its own array elements, instead of reusing the unrelated str_value/value_len left over from earlier processing. Fixes: 4b2672ec71a3 ("platform/x86: hp-bioscfg: order-list-attributes") Cc: stable@vger.kernel.org Signed-off-by: Muhammad Bilal --- drivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/drivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c b/d= rivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c index f09489a085c8..704c69c18146 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c @@ -261,7 +261,9 @@ static int hp_populate_ordered_list_elements_from_packa= ge(union acpi_object *ord * Ordered list data is stored in hex and comma separated format * Convert the data and split it to show each element */ - ret =3D hp_convert_hexstr_to_str(str_value, value_len, &tmpstr, &tmp_le= n); + ret =3D hp_convert_hexstr_to_str(order_obj[elem].string.pointer, + order_obj[elem].string.length, + &tmpstr, &tmp_len); if (ret) goto exit_list; =20 --=20 2.55.0 From nobody Tue Sep 29 04:39:33 2026 Received: from mail-wm1-f48.google.com (mail-wm1-f48.google.com [209.85.128.48]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6556943C05B for ; Wed, 12 Aug 2026 11:19:01 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.48 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786533542; cv=none; b=SOyV2Zpsr/nHjtd6K/yy8IaBFcBne13mWLuldhSVWwOoZ5AdJnuLvpZeB5kOMFtLSN3QbmtJYaBIhtJISPVtMdjJjZ0s3eGjL6ESpZUWBJVoVGr++OsF5R1M/FAi+Sd9FoExc17ZioNvVIVvWkTBneKa+YH1zIkSMGiFNhvZeLU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786533542; c=relaxed/simple; bh=jIs7SBmbrIzpQPWUe7SIDuER+UB8eqmz6Q8ZK68R+M0=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=pDs+ixZnujRvPqDd36dYbBmcGXARuzUeNXqRWH8BBIyfkhoMRXIL+S1NAKOoqsrtvgk87+SdZkA9wTs+engKYYKkYERpMykWucoAnkq3agB7SiH2RG+qfeDS/wxmdhw79QXnB3Jv/beE0v27G9+cWX88qYRE2RXdxsrNDX7WEbQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=GxQN42Le; arc=none smtp.client-ip=209.85.128.48 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="GxQN42Le" Received: by mail-wm1-f48.google.com with SMTP id 5b1f17b1804b1-4954f5e8020so3807755e9.2 for ; Wed, 12 Aug 2026 04:19:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786533539; x=1787138339; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=vM2gdPuCkyOEMq/7xYv9p7Pxqs4FlFaCZ91sPS1S74s=; b=GxQN42Le9+jE4vuEAj9Fc0uiESfs4mmBaDbPbbUgzhV59YjjLCbxQp912dLeFtO3Dk 4pfHu2qX4BXioPnFsqSOg9Id8EopLagEreYJ4/JN/jawQ/JjymfmBD+yOuayPz4eT5Lv USMxugUlpU46PaLbHJiNikOunvWkGXVOUrOOtjOSVj3cVi7Lx+G8lnKjnkpWNpnyltrb ZaS7y/DtXUn9BSLwQnwsdH56CFLOHAT9lW4PMTzIQM7GvPZ41jhALhAsGzcQRyjtm7Bm r3+iS88q4JiHAO2HA54TWu3WKXCnBZ06hW3exht9BALgoRzbzoZkmYlwm1wOPGGfxQWy nuMQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786533539; x=1787138339; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=vM2gdPuCkyOEMq/7xYv9p7Pxqs4FlFaCZ91sPS1S74s=; b=PNzKFmFfq/KSwSyTLvvAaj0+IP6a6hB82umCm5IkigQT3k6lDIfPvFqdPhFcASwcuI mlxwO7nstBjlaSWNDdwZNh8O1YmICFF/+9mIB9OKoyM3X0zt30JyJPGUlWRkaYeL5k/p 3DMsWEjmZUKRI9ecuI1x4PoepPUyFlzQsvYzzq2Q+PXTjpKy/A6YI5qF+lUAaZ1m4M76 rhHqF5r+BhKfORTTJgEk06bRjLypSjlqt1OhrXUf/X6yYac/0pZKJ2RjMtbnwH7ttDZt obWgBNSy0INa4RkvlvVcPEvtHY+ibjydQ3RGStFux4yT4Npp+67muULT26vZZ/El31LL FS1g== X-Forwarded-Encrypted: i=1; AHgh+Ros1rTjzV70RnycuE+JDXA2w/Hl6SSSpB/PoJhyBeVmPmTsyTR0EdHOYUFgikQffrJQUsVtaXBj7SdqH1k=@vger.kernel.org X-Gm-Message-State: AOJu0Ywl6UST/GHzTMhbpqkP7rw2P4aLf6YehP9DbP3t6Utgenn3khIq K2QYpep/vr9snhm2HcyWMFn1j5XDmD261Z/i6nujguriEehtE4f9yKXi X-Gm-Gg: AR+sD13lF4+QIssz+46irHCZ6dNS4LWOOXzHvsOu0s+G1EEYsr3zFmk4vip8RvYz+9o Y1/LQkNJTuEjYYVadolqneJF3n8N+iwojIi313EH1bqb2WTPnQIZk/frBGbvI2f/qzBCrsFo6Rc hk9u5cTQueoMr+dLjmk7xaufrHjHCqB+D1aTb975ddbVnwZVIWcxpMcQg6X2jd62ejtQmIbnCq1 QB4hGvw+QgAFrKB/OT+8sN42ToIyeMAqwGfpdpXnSvTWOovbKXjDp9rMH4F5u58hB4XPsE//K56 KOJDxvfLXF0pA8aZ2QumyFpUJeloKGL5wqiMsMtUvoDQoTM47WVQ3su9fmIm7sDtzt5h4+QIM4P mTItjwdE0Gef2jijRjAGbDd6YkrgJQ3dHHfDnvSTDlL934i5d6bN7tlX9OOVFFaypNOWneta03G etgPC9xBN0ikRSZN4YnLp/xXfQUZ+V2qniLEieYVqjgV3SfUPbY6twV9sW6MaGGjSDqEwdnou4b hFBpEheHF4jVaTxrgKLi6uno6IBvBnpIsPh2c9lpQ== X-Received: by 2002:a05:600c:468f:b0:499:4892:e84e with SMTP id 5b1f17b1804b1-4997c14569amr44988515e9.11.1786533539249; Wed, 12 Aug 2026 04:18:59 -0700 (PDT) Received: from fedora ([202.47.63.86]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48150d702c9sm6670072f8f.34.2026.08.12.04.18.56 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 12 Aug 2026 04:18:58 -0700 (PDT) From: Muhammad Bilal To: platform-driver-x86@vger.kernel.org Cc: jorge.lopez2@hp.com, hansg@kernel.org, ilpo.jarvinen@linux.intel.com, linux@weissschuh.net, linux-kernel@vger.kernel.org, stable@vger.kernel.org, Muhammad Bilal Subject: [PATCH v2 9/9] platform/x86: hp-bioscfg: advance elem past consumed array elements Date: Wed, 12 Aug 2026 16:18:29 +0500 Message-ID: <20260812111829.172273-10-meatuni001@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260812111829.172273-1-meatuni001@gmail.com> References: <20260812111829.172273-1-meatuni001@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The outer parsing loop in each attribute-type parser advances "elem" (the index into the ACPI package element array) by exactly one per iteration, but cases that consume multi-element arrays (PREREQUISITES, ENUM_POSSIBLE_VALUES, PSWD_ENCODINGS) read "size" consecutive elements without adjusting "elem" for the extra entries consumed beyond the first. The next outer iteration then re-reads a leftover element from the array just consumed instead of the next real property, and the type check fails on that stale element, aborting the parse with -EIO. This produces exactly the failure visible in dmesg on the test hardware, on every boot: Error expected type 2 for elem 13, but got type 1 instead hp_bioscfg: Returned error 0x3, "Invalid command value/Feature not supported" Fix by advancing "elem" by (size - 1) after each array-consuming loop, so the outer loop's own "elem++" lands on the correct next element. "eloc" is intentionally left alone: it indexes the logical property schema, not the physical element array, and each array case is still exactly one logical property regardless of how many physical elements it spans. The defect is identical across all five attribute-type parsers (enum, integer, string, ordered-list, password), which were copy-pasted from the same template when the driver was introduced. Fixes: 6b2770bfd6f9 ("platform/x86: hp-bioscfg: enum-attributes") Fixes: 6f2c06d5a467 ("platform/x86: hp-bioscfg: int-attributes") Fixes: e6c7b3e15559 ("platform/x86: hp-bioscfg: string-attributes") Fixes: 4b2672ec71a3 ("platform/x86: hp-bioscfg: order-list-attributes") Fixes: 8646a3b5ee3a ("platform/x86: hp-bioscfg: passwdobj-attributes") Cc: stable@vger.kernel.org Signed-off-by: Muhammad Bilal --- drivers/platform/x86/hp/hp-bioscfg/enum-attributes.c | 4 ++++ drivers/platform/x86/hp/hp-bioscfg/int-attributes.c | 2 ++ drivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c | 2 ++ drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c | 4 ++++ drivers/platform/x86/hp/hp-bioscfg/string-attributes.c | 2 ++ 5 files changed, 14 insertions(+) diff --git a/drivers/platform/x86/hp/hp-bioscfg/enum-attributes.c b/drivers= /platform/x86/hp/hp-bioscfg/enum-attributes.c index af4d1920d488..43beb639051e 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/enum-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/enum-attributes.c @@ -227,6 +227,8 @@ static int hp_populate_enumeration_elements_from_packag= e(union acpi_object *enum kfree(str_value); str_value =3D NULL; } + if (size) + elem +=3D size - 1; break; =20 case SECURITY_LEVEL: @@ -280,6 +282,8 @@ static int hp_populate_enumeration_elements_from_packag= e(union acpi_object *enum kfree(str_value); str_value =3D NULL; } + if (size) + elem +=3D (size < MAX_VALUES_SIZE ? size : MAX_VALUES_SIZE) - 1; break; default: pr_warn("Invalid element: %d found in Enumeration attribute or data may= be malformed\n", elem); diff --git a/drivers/platform/x86/hp/hp-bioscfg/int-attributes.c b/drivers/= platform/x86/hp/hp-bioscfg/int-attributes.c index d96e160953e3..5373af71549a 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/int-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/int-attributes.c @@ -243,6 +243,8 @@ static int hp_populate_integer_elements_from_package(un= ion acpi_object *integer_ kfree(str_value); str_value =3D NULL; } + if (size) + elem +=3D size - 1; break; =20 case SECURITY_LEVEL: diff --git a/drivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c b/d= rivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c index 704c69c18146..6696255738ba 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/order-list-attributes.c @@ -232,6 +232,8 @@ static int hp_populate_ordered_list_elements_from_packa= ge(union acpi_object *ord kfree(str_value); str_value =3D NULL; } + if (size) + elem +=3D size - 1; break; =20 case SECURITY_LEVEL: diff --git a/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c b/dr= ivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c index 6bd56d3f5bd0..9b989ef756ea 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c @@ -321,6 +321,8 @@ static int hp_populate_password_elements_from_package(u= nion acpi_object *passwor str_value =3D NULL; =20 } + if (size) + elem +=3D size - 1; break; case SECURITY_LEVEL: password_data->common.security_level =3D int_value; @@ -367,6 +369,8 @@ static int hp_populate_password_elements_from_package(u= nion acpi_object *passwor str_value =3D NULL; =20 } + if (size) + elem +=3D size - 1; break; case PSWD_IS_SET: password_data->is_enabled =3D int_value; diff --git a/drivers/platform/x86/hp/hp-bioscfg/string-attributes.c b/drive= rs/platform/x86/hp/hp-bioscfg/string-attributes.c index fe5a9a3a4ef1..5abec8995911 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/string-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/string-attributes.c @@ -233,6 +233,8 @@ static int hp_populate_string_elements_from_package(uni= on acpi_object *string_ob kfree(str_value); str_value =3D NULL; } + if (size) + elem +=3D size - 1; break; =20 case SECURITY_LEVEL: --=20 2.55.0