Re: [PATCH v4 8/9] platform/x86: hp-bioscfg: NUL-terminate the SPM auth token

From: Ilpo Järvinen

Date: Mon Oct 05 2026 - 09:41:34 EST


On Sat, 3 Oct 2026, Muhammad Bilal wrote:

> auth_token_store() copies the token with kmemdup(), which does not NUL
> terminate it, but hp_calculate_security_buffer() and
> hp_populate_security_buffer() treat it as a C string and read past the
> allocation.

Again here.

If something is treated as C string later, how is it valid to prepare it
with kmemdup_nul()? I just don't follow that logic.

Either something is a string or it isn't, which way this is?

> A lone newline (echo > auth_token) is worse: kmemdup() of 0 bytes
> returns ZERO_SIZE_PTR, which passes the NULL checks, so a later
> attribute write calls strlen() on address 0x10.
>
> Use kmemdup_nul(), which allocates one extra byte for the terminator
> and never returns ZERO_SIZE_PTR.
>
> Compile tested only.
>
> Fixes: b2715aa2e135 ("platform/x86: hp-bioscfg: spmobj-attributes")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Muhammad Bilal <meatuni001@xxxxxxxxx>
> ---
> Changes in v4:
> - New patch
>
> drivers/platform/x86/hp/hp-bioscfg/spmobj-attributes.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/drivers/platform/x86/hp/hp-bioscfg/spmobj-attributes.c b/drivers/platform/x86/hp/hp-bioscfg/spmobj-attributes.c
> index f0eb5c445..19f0f9f16 100644
> --- a/drivers/platform/x86/hp/hp-bioscfg/spmobj-attributes.c
> +++ b/drivers/platform/x86/hp/hp-bioscfg/spmobj-attributes.c
> @@ -316,7 +316,7 @@ static ssize_t auth_token_store(struct kobject *kobj,
> length--;
>
> /* allocate space and copy current auth token */
> - bioscfg_drv.spm_data.auth_token = kmemdup(buf, length, GFP_KERNEL);
> + bioscfg_drv.spm_data.auth_token = kmemdup_nul(buf, length, GFP_KERNEL);
> if (!bioscfg_drv.spm_data.auth_token) {
> ret = -ENOMEM;
> goto exit_token;
>

--
i.