Re: [PATCH v4] platform/x86: hp-bioscfg: fix 16-byte heap overflow for empty auth token
From: Ilpo Järvinen
Date: Mon Oct 05 2026 - 11:40:52 EST
On Sat, 19 Sep 2026 11:00:37 +0500, Muhammad Bilal wrote:
> hp_calculate_security_buffer() special-cases an empty authentication
> string and returns a fixed 4 bytes (sizeof(u16) * 2). But
> hp_populate_security_buffer() does not special-case that same input:
> for any authentication string that does not start with BEAM_PREFIX,
> including the empty string, it always builds "UTF_PREFIX +
> authentication" and converts the result to UTF-16, writing a 2-byte
> length header plus 2 bytes per character of "<utf-16/>" (9 characters),
> 20 bytes total, regardless of how long "authentication" itself is.
>
> [...]
Thank you for your contribution, it has been applied to my local
review-ilpo-next branch. Note it will show up in the public
platform-drivers-x86/review-ilpo-next branch only once I've pushed my
local branch there, which might take a while.
FYI [if applicable to your patch], as per Linus' policy change, also
fixes are mostly routed through for-next unless the fix is for a
commit introduced in the most recent cycle or is clearly a regression
fix.
The list of commits applied:
[1/1] platform/x86: hp-bioscfg: fix 16-byte heap overflow for empty auth token
commit: 67e222d412cc51d05380f2b7482a998cd4b4c638
--
i.