Re: [PATCH v2 1/3] platform/x86: hp-bioscfg: fix OOB reads in hp_get_string_from_buffer()
From: Andy Shevchenko
Date: Mon Sep 28 2026 - 17:26:59 EST
On Mon, Sep 28, 2026 at 11:03 PM Muhammad Bilal <meatuni001@xxxxxxxxx> wrote:
>
> The escape-prescan loop uses 'size' as both loop bound and
> accumulator, so each match extends the bound and reads past src[]:
>
> for (i = 0; i < size; i++)
> if (src[i] == '\\' || ...) size++;
>
> Snapshot the real char count into orig_size and loop against that.
>
> Also fix two adjacent issues: the bounds check omits the 2-byte
> length prefix already consumed, and utf16s_to_utf8s() receives the
> byte count (src_size) instead of the u16-unit count (orig_size).
>
> Tested on HP EliteBook 840 G2 (Fedora 44, Linux 7.2.7).
...
> int hp_get_string_from_buffer(u8 **buffer, u32 *buffer_size, char *dst, u32 dst_
> u16 *src = (u16 *)*buffer;
> u16 src_size;
>
While at it, drop this blank line.
> + u16 orig_size;
> u16 size;
> int i;
> int conv_dst_size;
--
With Best Regards,
Andy Shevchenko