[PATCH v2 0/3] platform/x86: hp-bioscfg: string buffer and password fixes

From: Muhammad Bilal

Date: Mon Sep 28 2026 - 16:03:43 EST


This series addresses string buffer issues and password validation
in the hp-bioscfg driver.

Patch 1 fixes bounds checking, prescan OOB read, and character count
accounting in hp_get_string_from_buffer().

Patch 2 replaces the truncating manual conversion loop with a two-stage
conversion: utf16s_to_utf8s() into a scratch buffer followed by
string_escape_mem().

Patch 3 fixes validate_password_input() returning positive
INVALID_BIOS_AUTH (0x0E), which caused userspace writes of
out-of-range passwords to appear successful.

All patches tested on HP EliteBook 840 G2 (Fedora 44, Linux 7.2.7).

Changes in v2:
- Split hp_get_string_from_buffer() fixes into two logical patches
(bounds/OOB reads and UTF-8 conversion rewrite), as reviewed by
Ilpo Järvinen.
- Dropped lib/string_helpers patch: pass "\\\r\n\t" to string_escape_mem()
with existing flags (ESCAPE_SPACE | ESCAPE_SPECIAL) to escape the four
characters without altering quotes, as reviewed by Andy Shevchenko.
- Added password validation errno fix as patch 3/3.

Muhammad Bilal (3):
platform/x86: hp-bioscfg: fix OOB reads in hp_get_string_from_buffer()
platform/x86: hp-bioscfg: fix non-ASCII truncation in
hp_get_string_from_buffer()
platform/x86: hp-bioscfg: return -ERANGE from
validate_password_input()

drivers/platform/x86/hp/hp-bioscfg/bioscfg.c | 77 ++++++-------------
.../x86/hp/hp-bioscfg/passwdobj-attributes.c | 6 +-
2 files changed, 27 insertions(+), 56 deletions(-)

--
2.55.0