Re: [PATCH v4 1/9] platform/x86: hp-bioscfg: fix OOB reads in hp_get_string_from_buffer()
From: Andy Shevchenko
Date: Sat Oct 03 2026 - 16:15:09 EST
On Sat, Oct 03, 2026 at 12:14:26AM +0500, Muhammad Bilal wrote:
> The escape prescan loop uses 'size' as both its bound and its
> accumulator, so each escape character found extends the loop and
> reads past the end of src[].
>
> Use the original u16 count as the loop bound. Also include the 2-byte
> length prefix in the bounds check, pass the u16 count instead of the
> byte count to utf16s_to_utf8s(), and advance the buffer by the bytes
> actually consumed instead of the escape-inflated count.
>
> Tested on HP EliteBook 840 G2 (Fedora 44, Linux 7.2.7).
...
> - /* Ensure there is enough space remaining to read and convert
> - * the string
> + /* Ensure there is enough space remaining for the length prefix
> + * just read plus the string data it describes.
> */
/*
* While at it, fix the comment style for
* multi-line comments. You can use this example.
*/
--
With Best Regards,
Andy Shevchenko