[PATCH v3 0/2] platform/x86: hp-bioscfg: fix empty auth token overflow and clean up audit log loop

From: Muhammad Bilal

Date: Tue Aug 18 2026 - 15:12:28 EST


Hi Ilpo,

This is v3 for the remaining two patches (patches 4 and 5) from the v2
series [2], addressing your review feedback:

- Patch 1/2 (was patch 4 in v2): Remove the special-case "if (!authlen)"
return entirely in hp_calculate_security_buffer(). The generic
calculation already naturally yields 20 bytes for empty strings,
eliminating duplicate logic and fixing the 16-byte heap overflow
(reported earlier by Josh Snyder [3]).

- Patch 2/2 (was patch 5 in v2): Remove the dead inner bounds check in
audit_log_entries_show() since "count * LOG_ENTRY_SIZE > PAGE_SIZE" is
already checked prior to entering the loop, and clean up the redundant
"else" block after "break".

Changes in v3:
- Patch 1/2: Remove the "if (!authlen)" check completely instead of
adjusting the formula, avoiding code duplication as suggested by
Ilpo Järvinen.
- Patch 2/2: Remove the dead loop check and the redundant else block
instead of adjusting loop boundary math.

Changes in v2:
- Squashed v1 patches 9-13 into a single patch (applied in
review-ilpo-next).

Link: https://lore.kernel.org/r/20260803143037.93105-1-meatuni001@xxxxxxxxx [1]
Link: https://lore.kernel.org/r/20260812111829.172273-1-meatuni001@xxxxxxxxx [2]
Link: https://lore.kernel.org/r/20260402-hp-bioscfg-overflow-v1-1-6985f8c9e67c@xxxxxxxxxxx [3]

Muhammad Bilal (2):
platform/x86: hp-bioscfg: fix 16-byte heap overflow for empty auth
token
platform/x86: hp-bioscfg: remove dead bounds check in
audit_log_entries_show

drivers/platform/x86/hp/hp-bioscfg/spmobj-attributes.c | 4 ----
drivers/platform/x86/hp/hp-bioscfg/surestart-attributes.c | 9 +++------
2 files changed, 3 insertions(+), 10 deletions(-)

--
2.43.0