[PATCH v4 5/9] platform/x86: hp-bioscfg: fix off-by-one in password length check
From: Muhammad Bilal
Date: Fri Oct 02 2026 - 15:20:27 EST
current_password and new_password hold MAX_PASSWD_SIZE bytes including
the NUL, but validate_password_input() accepts a password of exactly
MAX_PASSWD_SIZE characters when the firmware limits allow it.
strscpy() then truncates it and fails with -E2BIG, which
store_password_instance() ignores, so the write reports success with a
truncated password stored.
For example, with a max_password_length of 64 or more, writing 64
characters succeeds but only 63 are stored.
Reject lengths of MAX_PASSWD_SIZE or more.
Compile tested only.
Fixes: 8646a3b5ee3a ("platform/x86: hp-bioscfg: passwdobj-attributes")
Signed-off-by: Muhammad Bilal <meatuni001@xxxxxxxxx>
---
Changes in v4:
- New patch
drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c b/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c
index f0551b455..a2f50ecbe 100644
--- a/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c
+++ b/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c
@@ -74,7 +74,7 @@ static int validate_password_input(int instance_id, const char *buf,
if (is_current && !length)
return 0;
- if (length > MAX_PASSWD_SIZE)
+ if (length >= MAX_PASSWD_SIZE)
return -E2BIG;
if (password_data->min_password_length > length ||
--
2.43.0