[PATCH v4 9/9] platform/x86: hp-bioscfg: fix oops on short integer attribute buffer

From: Muhammad Bilal

Date: Fri Oct 02 2026 - 15:21:10 EST


hp_populate_integer_elements_from_buffer() ignores the return value of
hp_get_string_from_buffer(). When fewer than 2 bytes are left in the
buffer, dst_size is 0, kcalloc() returns ZERO_SIZE_PTR and
hp_get_string_from_buffer() fails without writing to it, so
kstrtoint() faults on address 0x10.

Return the error instead.

Compile tested only.

Fixes: 6f2c06d5a467 ("platform/x86: hp-bioscfg: int-attributes")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Muhammad Bilal <meatuni001@xxxxxxxxx>
---
Changes in v4:
- New patch

drivers/platform/x86/hp/hp-bioscfg/int-attributes.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)

diff --git a/drivers/platform/x86/hp/hp-bioscfg/int-attributes.c b/drivers/platform/x86/hp/hp-bioscfg/int-attributes.c
index a27907066..14317b7fd 100644
--- a/drivers/platform/x86/hp/hp-bioscfg/int-attributes.c
+++ b/drivers/platform/x86/hp/hp-bioscfg/int-attributes.c
@@ -331,7 +331,12 @@ static int hp_populate_integer_elements_from_buffer(u8 *buffer_ptr, u32 *buffer_
// VALUE:
integer_data->current_value = 0;

- hp_get_string_from_buffer(&buffer_ptr, buffer_size, dst, dst_size);
+ ret = hp_get_string_from_buffer(&buffer_ptr, buffer_size, dst, dst_size);
+ if (ret < 0) {
+ kfree(dst);
+ return ret;
+ }
+
ret = kstrtoint(dst, 10, &integer_data->current_value);
if (ret)
pr_warn("Unable to convert string to integer: %s\n", dst);
--
2.43.0