From nobody Mon Sep 28 08:01:21 2026 Received: from mail-pj1-f43.google.com (mail-pj1-f43.google.com [209.85.216.43]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3D36E395ADA for ; Mon, 24 Aug 2026 22:56:45 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.43 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787612206; cv=none; b=jroCwuXntATUWMAEDsS0U1+UkBXxOlyx5CMMu3P4ovWbyQiJs9cmypPkTBA7euaIF3sshhPw/NuAXQ9N3+wUgjtta6IAlai6iptj7TGPMenJFU9Zv4sDOYpEo7lmGd5Y45sLkpQxLdfcUSXODzftZ4QM83SBb6EaEooFNGP5Xu4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787612206; c=relaxed/simple; bh=bZ4mr1I+U3yQOcHz6Hb3G8cgJFdB2crR9bfGO93EcxQ=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Q1M6gZissVMOOhzksK6NeT/XGWxWg+dsJLJAFoFmDOexiahEa+UCAMnaurnZ4FbUsxyCe7bZUgGTuq29czcyffnUUaynaJ9VqDFp884V0HvNJq4nJfzjaP2V9M/QouCpMX00ZynxzVWhfzsxMV8eL6zjxQBE5zkVig8MdpfqnnU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=DTD6BGVV; arc=none smtp.client-ip=209.85.216.43 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="DTD6BGVV" Received: by mail-pj1-f43.google.com with SMTP id 98e67ed59e1d1-38759bcd877so5061706a91.2 for ; Mon, 24 Aug 2026 15:56:45 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787612204; x=1788217004; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=/9Tw605kJhO/LEd8BNi1zuUQuVwSe01S9ZMwxtVDwiw=; b=DTD6BGVVBaztfIxvOtHQiNN6sf6RmZxqmXpCGTSejrbPhEBYrRQaeTMdRg3cYndJLY 2DwThrpbCYCgDlHXvODNrHhLvFgSseTVTeYGwzK4MQwpHmggHg9wauY8SIlpU2OaPmr4 gou72JIPt3RsOfGrgYZ5qLOfYckuftaigV/ciipdR+mFl8qZd6UoEBakNj8IfEF3v5nh WFtnIG8qFAJrK1KLB5yUQbiogLLRhKLpgdyc4vpMyRITtC3RspFAuNz5YTY2LZesGK7E ZvRrz0WLXBuINsqcfMWz7/yYxjYEETiIMt2flMLeTKDv5O0PB08Cs1WfCUn3EMb16jz/ XyYg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787612204; x=1788217004; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=/9Tw605kJhO/LEd8BNi1zuUQuVwSe01S9ZMwxtVDwiw=; b=cMzvy7vSJu+KaBde1LsrjzUYw6+2tpcv4HPcigxWFqbrCrO4uZVSRBqFFC7m3onFcq wanOG67ZqFbxwDcTkjCKW56HX2F4gMp5oPaGG14TO/eJWU4MGbR++sYlPjJGHG2RgJq5 2p3+JpcIydHoZAqg/UIL7DHzP4FfO377N322q1p55gzfH7UI9l8oTCtUPe0ykpcMde1o i6Pqf98/PRWODRMKbYqekVzObh6C+isXhYYqIVAKfWSvymxtg/f/jQlWVPKn9dVVAMNS xGE+nQ8ZzlJ9hZwiGZhGdEbkeM1QrvgB6KsARbxVb6AlUZDZZ59cE7V64YhK0yax/BEU PH6A== X-Forwarded-Encrypted: i=1; AHgh+Rp486Kw70OZP/yCc2G7Kt8eEj9zonNXGwkaOFS35Ur/lxtvCX06JMvIPd/prfZZpUR5u3lK55L7kNfLg3k=@vger.kernel.org X-Gm-Message-State: AFuF++mWw3l5C9adyf00ARKukHW8mn9gJbW+3VKDpPXv3771A7J8L0SZ y/pa6gTWlVqmUho/K08NNIS5uwbaUBVUgBN0aek7/r3t9iu4pnOYmcJl X-Gm-Gg: AR+sD10mOCD5vx39SpHij9ETQTYhoi4aa80uB6EDCfhjfgNDPfcsiMEywfnZrOPMM5E jkskC9TAYxm/agOWXR0jAlBI6aaxAj1uwIJe1ePSYo1unRxSpuklv7EAOxBR8zfDQuakI93xbrU kjSNsNm/u6PAzhSuheHowHmnmjNTBRcbxcNWdJsr+OWUqJoYf6xOgkmmgysG6NvcBhRPTf2luAr p7+MNpOf5TyM9ZGBre/Rv9WnG0ySrDypIUIqmTInOhq1mn5czR3NcCuGvVVncBk6qZrpCvXMles Se8l9YlFaubPlGcOUnM1oucSZKtRHf08C/bAMJyAqFemRJo0eCcjvW1bsTgtN/L8sdd6bn757qC Wa4gc3S2BJCSwLM+cKIrYHAE4NAYIvgBEkotwtm5ts0nIfhX8rI2N0NLvzP35N4cIEWSE391HnY Q7nc40JW3MjZ+zVumkF0xwGsA2I6zZZzc3UhcRRjHfozaDYdHLhJapUtC3hSB8Gc32/fne9T0gt +pSBSyGNzaetK/TgtD6YArfBLpKZr4O40j/3nhDGAKlANeVvP8K X-Received: by 2002:a17:90b:39ab:b0:393:19a3:4e5 with SMTP id 98e67ed59e1d1-395df686f1dmr38241564a91.16.1787612204546; Mon, 24 Aug 2026 15:56:44 -0700 (PDT) Received: from fedora ([202.47.63.86]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-328272232besm1527287eec.21.2026.08.24.15.56.35 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 24 Aug 2026 15:56:44 -0700 (PDT) From: Muhammad Bilal To: jorge.lopez2@hp.com, hansg@kernel.org, ilpo.jarvinen@linux.intel.com, linux@weissschuh.net Cc: platform-driver-x86@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org, Muhammad Bilal Subject: [PATCH 1/2] platform/x86: hp-bioscfg: fix OOB read in hp_get_integer_from_buffer() on unaligned input Date: Tue, 25 Aug 2026 03:56:09 +0500 Message-ID: <20260824225610.18471-2-meatuni001@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260824225610.18471-1-meatuni001@gmail.com> References: <20260824225610.18471-1-meatuni001@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" hp_get_integer_from_buffer() aligns the read pointer before dereferencing it: int *ptr =3D PTR_ALIGN((int *)*buffer, sizeof(int)); When *buffer is not 4-byte aligned, PTR_ALIGN() advances ptr forward by 1-3 bytes to reach the next aligned address. The bounds check that follows does not account for that advance: if (*buffer_size < sizeof(int)) return -EINVAL; This only confirms 4 bytes remain from the original *buffer, not from the aligned ptr. If *buffer is unaligned and *buffer_size is between 4 and (pad + 3) bytes, *(ptr++) reads up to 3 bytes past the end of the buffer. *buffer_size is also under-decremented on every call, aligned or not: *buffer_size -=3D sizeof(int); *buffer is advanced to the aligned, post-read position, but *buffer_size only accounts for the 4 bytes of the integer itself, not the alignment padding skipped to reach it. Each unaligned read leaves *buffer_size overstating the true remaining space by the pad amount, an error that compounds across repeated calls against the same buffer (hp_get_common_data_from_buffer() calls this in a sequence), making later bounds checks against *buffer_size progressively less reliable. Compute the padding explicitly, check for it, and account for it when advancing *buffer_size, so the pointer and the remaining-length count stay consistent with each other. Fixes: a34fc329b189 ("platform/x86: hp-bioscfg: bioscfg") Cc: stable@vger.kernel.org Signed-off-by: Muhammad Bilal --- drivers/platform/x86/hp/hp-bioscfg/bioscfg.c | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/drivers/platform/x86/hp/hp-bioscfg/bioscfg.c b/drivers/platfor= m/x86/hp/hp-bioscfg/bioscfg.c index 0edc6e7cfa9a..32b99a862082 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/bioscfg.c +++ b/drivers/platform/x86/hp/hp-bioscfg/bioscfg.c @@ -39,14 +39,18 @@ struct kobj_attribute common_display_langcode =3D int hp_get_integer_from_buffer(u8 **buffer, u32 *buffer_size, u32 *integer) { int *ptr =3D PTR_ALIGN((int *)*buffer, sizeof(int)); + u32 pad =3D (u8 *)ptr - *buffer; =20 - /* Ensure there is enough space remaining to read the integer */ - if (*buffer_size < sizeof(int)) + /* + * Ensure there is enough space remaining to read the integer, + * including any padding PTR_ALIGN() introduced to reach it. + */ + if (*buffer_size < pad + sizeof(int)) return -EINVAL; =20 *integer =3D *(ptr++); *buffer =3D (u8 *)ptr; - *buffer_size -=3D sizeof(int); + *buffer_size -=3D pad + sizeof(int); =20 return 0; } --=20 2.55.0 From nobody Mon Sep 28 08:01:21 2026 Received: from mail-pf1-f169.google.com (mail-pf1-f169.google.com [209.85.210.169]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C2314394462 for ; Mon, 24 Aug 2026 22:56:55 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.169 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787612218; cv=none; b=PpjwxkWYyP6p4ard9tZ6luOb3KipEve676JdsORD8tAQSzqVG3C2DSzBw5qdmRmLmt2QT8QlzirNFqfZrHvVdpwTKsKOV5BpgGA8Rh3FWPpoXJ1j78uZ60iw7wNN2x2E7OMlS1iCdatb1J9JLUB8m0pbyEoMrbKmGlv83Yc7J5A= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787612218; c=relaxed/simple; bh=elKExN1J7zD4RfHDPagIeby5Ykxf3Fr0hY9ChnwLDDg=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=esFWxUoFqNru/Smj0k9y/ZEcw8Nl37uRnlXB74jYRUCB5omhYTV8K0dEgD0rPLzcLPSmGPt/uPBHCN3GuWDEKwrgYXKHhgJH8Xvvyv+3Ki2Tca+aUp65hubtt/mmwQpVRdQUvHzJqb3NCFLQPtVAnjNjbZ0y3OEF23tbYlPSOLk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=sGtqFYBK; arc=none smtp.client-ip=209.85.210.169 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="sGtqFYBK" Received: by mail-pf1-f169.google.com with SMTP id d2e1a72fcca58-8487214ad2bso5411525b3a.1 for ; Mon, 24 Aug 2026 15:56:55 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787612215; x=1788217015; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Sl4hvJNpXpXY2ovKfwEbjj0KIAJXLs4vfK9AJ7noW9U=; b=sGtqFYBKD0axA6KAC+B/WOYKi4bJCy8kJoCqy74OkN+AyuNQtK7qiul4kSsGPfWjZR vlrDdMDycVA2llXdHSrb5Ewnj1wOAYwMWBxTDspWEMWT3kK6ACx6luTLJbLrc4sFPq+5 9cKFNbvuvjkRkYzoNRpf0zxhvTQrG/lT3+XtstNFRG57GR60MonZGOM42Cy3oUpacVXp nGyaHMaEvElgNbqQ+xiV3EvwGckAYTxWQz+VYHt/oP6rZksTE5ysTWAEq4gTGDvlWVoE ETgwpfWZcUbULHUaxDDq1AP1O6skAb7y/s9H8S+KEJiCNQpC/CvHYa1jBGsMR4Lllr/X CS5g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787612215; x=1788217015; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=Sl4hvJNpXpXY2ovKfwEbjj0KIAJXLs4vfK9AJ7noW9U=; b=M5xUs0bQnCZ3C5XXjN6U0uinpucfBuvEKk4NuRMxGmCo4KzeL7mCerMSTAedKfCdSP dDRs5ZY/itPIVwxD7Zp/dvzmPV4sogfPtBy/dUxo6j+ke0SBOe1XRzHwVdPw+gay2EEV HaYKTBCn219aC3sPrX1TRTN9OjlAPktWbf24xGP0XFhCXFh7iGBVdAdZ93MMogVrLn2Z GC9gaashMDkrGLxkJvtgNBSBRs6Cbqj1zoew0RmsZsCda7AiyF6h0zYLVnXbM8o+GbQi stZyEdfAypkOvre6jEmmQFHQUHyhdLLUOiDYuYu3iLLYmYoytouVuNtQ+bn2PtH8RYCv ZbVA== X-Forwarded-Encrypted: i=1; AHgh+RoWwdUU3AhLDodhdubULq2Yi6rn4XBfe0WXvWEuVrWgOhoovDczkaOYnvJgJbX3k8Vd4/U8XszSIaZSxhw=@vger.kernel.org X-Gm-Message-State: AFuF++nkE6NZYMj/HkqxmKD6cC9aPdNtqM00JeMu+AU5V3sLD2MyhPuF POLNR+D6JyJHp+B6647/4SZp20BptkoG2IW8gLGDtPW0UV+XzUUor+67 X-Gm-Gg: AR+sD13oVazrEnRk3bg8AFDDGK9UEjaZSK7FSxlkIsorulJI+WvrQiJALLXPARSnG+Z CC8vLg0IxZCxaLXo7pLhrP7e0yXv5tN/wOpk1TxLiexv0TwzJPc1y4KB2PyuYdNYy8PPsW85TyU IfFBYc95Nry64aom7GnGR8vdY9SZRrSev28m++1/9oiVeY8YxWn2ZoKiJOtYwoWQj7wePkUMSlQ NLt9Y66bqRIyPjl5a5sFxjHeNm56ATzF9icYAW99Fk25Qs/WUVNEfxTNk5XyHNfGs9guWSET3xM 6Fs/UgTWbGZcfeboqOc+9N4YDjebX9awDEF6e2TNk01A7YJW1tnaycD32dqaOV0hfktajVwlwbk WEMQ35D0Jzf0JutGw3fnMbst2snCEAKRZ2keisgGien+ufD/mbOt9dTNYO9EuJnnwqJe172Xe47 Cf7tRFuk1XX6BDcuyzjnRkeahpfN1BJau0lFC6hPCy3H3/D13GfLX9cmBLXyw+Yw7lVKGSVpU5d tOxz7XdszMVlA3++ax6BFW36gRLOJehV+lRK9u62w== X-Received: by 2002:a05:6a21:320b:b0:3c8:e10b:7a9b with SMTP id adf61e73a8af0-3cd91367d07mr4264614637.16.1787612215051; Mon, 24 Aug 2026 15:56:55 -0700 (PDT) Received: from fedora ([202.47.63.86]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-328272232besm1527287eec.21.2026.08.24.15.56.45 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 24 Aug 2026 15:56:54 -0700 (PDT) From: Muhammad Bilal To: jorge.lopez2@hp.com, hansg@kernel.org, ilpo.jarvinen@linux.intel.com, linux@weissschuh.net Cc: platform-driver-x86@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org, Muhammad Bilal Subject: [PATCH 2/2] platform/x86: hp-bioscfg: fix heap OOB read and buffer desync in hp_get_string_from_buffer() Date: Tue, 25 Aug 2026 03:56:10 +0500 Message-ID: <20260824225610.18471-3-meatuni001@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260824225610.18471-1-meatuni001@gmail.com> References: <20260824225610.18471-1-meatuni001@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" hp_get_string_from_buffer() has several buffer boundary and memory safety bugs when parsing UTF-16 strings from WMI BIOS buffers: First, the loop that counts how many characters will need backslash- escaping uses the same variable as both the accumulator and the loop bound: size =3D src_size / sizeof(u16); ... for (i =3D 0; i < size; i++) if (src[i] =3D=3D '\\' || src[i] =3D=3D '\r' || src[i] =3D=3D '\n' || src[i] =3D=3D '\t') size++; Each escape character found extends size, which is also what i is compared against, so the loop keeps going past the buffer's true character count once any escape character is seen at or near the end of the valid range. Every escape character found causes one additional out-of-bounds src[i] read. Second, once conv_dst_size is computed, the conversion call passes the byte length instead of the character count: utf16s_to_utf8s(src, src_size, UTF16_HOST_ENDIAN, dst, conv_dst_size); utf16s_to_utf8s()'s inlen parameter is a count of u16 units: its main loop decrements inlen once and advances the source pointer by one wchar_t per character consumed. src_size here is a byte count (the code's own preceding comment, "size value in u16 chars", computes the true character count separately as src_size / sizeof(u16)), so passing it directly makes the conversion loop walk up to twice as many u16 units as the source buffer actually holds whenever maxout does not run out first. Third, the bounds check 'if (*buffer_size < src_size)' is checked after src++ has already stepped over the 2-byte prefix. If *buffer_size equals src_size, only src_size - 2 bytes remain, so reading src_size bytes reads 2 bytes past the end of the input buffer. Finally, at the end of the function, the pointer and remaining buffer size are adjusted using the escape-inflated size rather than the actual number of input bytes consumed from the WMI buffer (sizeof(u16) + src_size), causing the buffer pointer and remaining length to drift out of sync for subsequent property parsers. Fix these by: - Keeping the true, unmodified character count in a separate orig_size variable. - Checking *buffer_size against sizeof(u16) + src_size before reading. - Accurately advancing *buffer and *buffer_size by sizeof(u16) + src_size. Fixes: a34fc329b189 ("platform/x86: hp-bioscfg: bioscfg") Cc: stable@vger.kernel.org Signed-off-by: Muhammad Bilal --- drivers/platform/x86/hp/hp-bioscfg/bioscfg.c | 29 +++++++++++--------- 1 file changed, 16 insertions(+), 13 deletions(-) diff --git a/drivers/platform/x86/hp/hp-bioscfg/bioscfg.c b/drivers/platfor= m/x86/hp/hp-bioscfg/bioscfg.c index 32b99a862082..dd453a9b962f 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/bioscfg.c +++ b/drivers/platform/x86/hp/hp-bioscfg/bioscfg.c @@ -60,6 +60,7 @@ int hp_get_string_from_buffer(u8 **buffer, u32 *buffer_si= ze, char *dst, u32 dst_ u16 *src =3D (u16 *)*buffer; u16 src_size; =20 + u16 orig_size; u16 size; int i; int conv_dst_size; @@ -67,17 +68,16 @@ int hp_get_string_from_buffer(u8 **buffer, u32 *buffer_= size, char *dst, u32 dst_ if (*buffer_size < sizeof(u16)) return -EINVAL; =20 - src_size =3D *(src++); - /* size value in u16 chars */ - size =3D src_size / sizeof(u16); - - /* Ensure there is enough space remaining to read and convert - * the string - */ - if (*buffer_size < src_size) + src_size =3D *src; + if (*buffer_size < sizeof(u16) + src_size) return -EINVAL; =20 - for (i =3D 0; i < size; i++) + src++; + /* size value in u16 chars */ + orig_size =3D src_size / sizeof(u16); + size =3D orig_size; + + for (i =3D 0; i < orig_size; i++) if (src[i] =3D=3D '\\' || src[i] =3D=3D '\r' || src[i] =3D=3D '\n' || @@ -93,9 +93,12 @@ int hp_get_string_from_buffer(u8 **buffer, u32 *buffer_s= ize, char *dst, u32 dst_ conv_dst_size =3D dst_size - 1; =20 /* - * convert from UTF-16 unicode to ASCII + * Convert from UTF-16 unicode to ASCII. utf16s_to_utf8s() counts + * its length argument in u16 units, not bytes, so pass the + * original character count rather than src_size (bytes) or the + * escape-inflated size. */ - utf16s_to_utf8s(src, src_size, UTF16_HOST_ENDIAN, dst, conv_dst_size); + utf16s_to_utf8s(src, orig_size, UTF16_HOST_ENDIAN, dst, conv_dst_size); dst[conv_dst_size] =3D 0; =20 for (i =3D 0; i < conv_dst_size; i++) { @@ -121,8 +124,8 @@ int hp_get_string_from_buffer(u8 **buffer, u32 *buffer_= size, char *dst, u32 dst_ src++; } =20 - *buffer =3D (u8 *)src; - *buffer_size -=3D size * sizeof(u16); + *buffer +=3D sizeof(u16) + src_size; + *buffer_size -=3D sizeof(u16) + src_size; =20 return size; } --=20 2.55.0