Re: [PATCH v4 6/9] platform/x86: hp-bioscfg: fix heap OOB with embedded NUL in store paths
From: Ilpo Järvinen
Date: Mon Oct 05 2026 - 09:27:35 EST
On Sat, 3 Oct 2026, Muhammad Bilal wrote:
> The store handlers copy the input with kstrdup(), which stops at the
> first NUL, but pass the full write size to
> hp_enforce_single_line_input(). With an embedded NUL the copy is
> shorter than count, so the helper reads, and can write one byte, past
> the allocation.
>
> Writing "A\0" followed by 4093 bytes of "B" to current_password makes
> memchr() scan 4093 bytes past a 2-byte copy. On an HP EliteBook 840 G2
> running Linux 7.2.7 all 100 such writes fail with -EINVAL although the
> input has no newline, so memchr() matched one in the heap. A userspace
> replica under ASan reports the same 4095 byte read, 0 bytes after the
> 2-byte region.
>
> Use kmemdup_nul() so the copy is always count + 1 bytes long.
>
> Compile tested only.
>
> Fixes: 5f94f181ca25 ("platform/x86: hp-bioscfg: bioscfg-h")
> Fixes: 8646a3b5ee3a ("platform/x86: hp-bioscfg: passwdobj-attributes")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Muhammad Bilal <meatuni001@xxxxxxxxx>
I don't understand this change.
What is the usecase for using the input beyond the first NUL?
> ---
> Changes in v4:
> - New patch
>
> drivers/platform/x86/hp/hp-bioscfg/bioscfg.h | 2 +-
> drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c | 2 +-
> 2 files changed, 2 insertions(+), 2 deletions(-)
>
> diff --git a/drivers/platform/x86/hp/hp-bioscfg/bioscfg.h b/drivers/platform/x86/hp/hp-bioscfg/bioscfg.h
> index ac57d6eab..77cb9cac1 100644
> --- a/drivers/platform/x86/hp/hp-bioscfg/bioscfg.h
> +++ b/drivers/platform/x86/hp/hp-bioscfg/bioscfg.h
> @@ -326,7 +326,7 @@ enum hp_wmi_data_elements {
> int i; \
> int ret = -EIO; \
> \
> - attr_value = kstrdup(buf, GFP_KERNEL); \
> + attr_value = kmemdup_nul(buf, count, GFP_KERNEL); \
> if (!attr_value) \
> return -ENOMEM; \
> \
> diff --git a/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c b/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c
> index a2f50ecbe..6c123d7a5 100644
> --- a/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c
> +++ b/drivers/platform/x86/hp/hp-bioscfg/passwdobj-attributes.c
> @@ -93,7 +93,7 @@ static int store_password_instance(struct kobject *kobj, const char *buf,
> char *buf_cp;
> int id, ret = 0;
>
> - buf_cp = kstrdup(buf, GFP_KERNEL);
> + buf_cp = kmemdup_nul(buf, count, GFP_KERNEL);
> if (!buf_cp)
> return -ENOMEM;
>
>
--
i.