From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wr1-f45.google.com (mail-wr1-f45.google.com [209.85.221.45]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 43037412BF8 for ; Mon, 3 Aug 2026 14:31:05 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.45 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785767469; cv=none; b=Las6ZEXCK532dSXrOY2iq5JeiBTunSk81dZEmvOQkStpSAXP99iLaePIjhvS67TAXCLqqviUoKbwuNh//BOQwFUGvV4aq/aoMwkWgy6CoPQ0CzouBCvXWkMekdmRzTr0ojGC/Bzj+5HI0zOKR2WrGKEEY4SL97RWCtU6EJihXyM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785767469; c=relaxed/simple; bh=9EehTMGdJoM/pmPAG9mZtREZbrypCyCVR7Mvq/DwalQ=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=RVXKbVOvWMNdqP2gDIXN+4K78RDNydt1fXMu/mm+iTiWjiotoKac+2Sa2r4gunIcXKcXYdW5XCAvLmV4BprZ4ui8wS3qP6JAGVtpzyY5y15RiRgQqRYsiggBls7TyVuIvmM/sYDgjoN7DdbXmV3r2G0lf2nSXa7Z//yHTVhwomY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=Kn4k6TWc; arc=none smtp.client-ip=209.85.221.45 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="Kn4k6TWc" Received: by mail-wr1-f45.google.com with SMTP id ffacd0b85a97d-47f64ca1c2dso1006643f8f.2 for ; Mon, 03 Aug 2026 07:31:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785767464; x=1786372264; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=K+s/eo+/pWpLLFnoufPaOpVfgTjc+a46l3h08Co/MXY=; b=Kn4k6TWcQ7JqkozjWnJ65K7r0vJ3xuxicjgv4NL77v4z0s0+VpsKwj86jGriBrXlBC j6Xsu5PwruWz8XStm82TLY528+iK1V9P+1LBQ6/fHebJQHCyBEQY55JYsM4oBs3nqhl2 HQBiOPaFuzXyaTbyajGSPuFh3j4y1G0z01kpQq+6cQK+ssZrmgY1btEWbyyJ7SfLdWck wINc3bVOYlBzU+xErlNu3b4UcRzafDPuFcc8mpZdJ/krXbMDdNa7GV/ss2TXn8uv0pSh vksaSPwDL3GJ8YVxmbeoXV5zF+UNw6iXSaW86c0yNguZTG7Q+K+CfFLzwpqakp2d0UG9 v3Vg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785767464; x=1786372264; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=K+s/eo+/pWpLLFnoufPaOpVfgTjc+a46l3h08Co/MXY=; b=gDkX+jQREfkqgb0/96bfJbtoyi8VSFrLrWOaOIglO/jqf7yEF+x96sXDzXWmJ2U5xG N2qRLr3l5meEk7r8d6mgONk97ii/Izq+yRHIRLXA6Zb6oG2M24/EhELfRZOvmZQMvdnm X38r5MfJRnewSpDehShjoWsRseWWrP3ZiEiYAevQxVd5ddv2Y460tjfCw80kSW1AXqju UxwupuJD6aMVvkAsR9OpYCnkC+UYUewGSO7/Vtdq/pMlWLRqyXZgpEzC40weY6aVeVPl SbzYlJOR8cNJ+1avHddFaGjZ8zN/XHZKcIz2efzPsDEzO+R+X6g+QhxdZgm3mEtA/ffJ /dxA== X-Forwarded-Encrypted: i=1; AHgh+RpYhakxeldtQJw8jqfI9s2BfJYmqGTACAopkc/eLyoQsLuLpQ/a9ao6GyLt/6R9ddEWi4DfF8qB0XR3PQA=@vger.kernel.org X-Gm-Message-State: AOJu0YzywisRgbJRCDEJ50ZqnQh9VVsiaz9iRvxkr+jZvUZJAVuWNQ7O DGo44uEFGX5vZQH2yW7x68pXYwlTmv/8fY2mTaM51aZMe9vnGGeLDbA2 X-Gm-Gg: AR+sD13Y8ZGgbMCIIJo8Ue3EEPik8FF1bdQKOvaeUvo+HZpv3FoXzhAXoEHt1+mwNqc DDoZWZsRyGn7CitbIenlXRNYiTCx3BkvuZ5uLQtcP8Dsh9juUGpLjn+SsajuNaS2znJl8l2kWlx hiUEDhz4IUXGDjXMqog55Pi59l6zFMvQA4pVfmR70Br8197snS8Uktoqc5GKwLDMbb1mLFEjhgK 5lVHcriMk68hRQ7yZjVLqrFobkt2+9gj5k/SIZrD6q1jIKLZynOqfgpi8Io5mkcY413iRfKG4mF SwGBRZbhEYRFiq458avsNvy3oYC7CMs36Mjtej6gwlpSJe7us1edNiWzEYt2VVG63E67wylSFiB tM9cG5RaLALg7ktMnnKkOEMYXh6qy0kqzSUIZt/vWY8Nad3QnlrLhgnADCmtEJwP2zS/b6fZdFx QPmLxIlIgR8R8fa5rrP6Ospwkqc78LwGpibu8drE7gYZ1jAE4hCFQBDNndV4ZyPnEcVeAJQh/1+ RdUbDyoZzdWefn+mzE9VVs63E3Z1jJk+oNCmlQ7R4E= X-Received: by 2002:a05:600c:5395:b0:493:faf3:3ea5 with SMTP id 5b1f17b1804b1-4980c66c751mr293605105e9.4.1785767463425; Mon, 03 Aug 2026 07:31:03 -0700 (PDT) Received: from fedora ([202.47.63.86]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49807b98284sm236575295e9.12.2026.08.03.07.31.00 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 03 Aug 2026 07:31:02 -0700 (PDT) From: Muhammad Bilal To: platform-driver-x86@vger.kernel.org Cc: jorge.lopez2@hp.com, hansg@kernel.org, ilpo.jarvinen@linux.intel.com, linux@weissschuh.net, linux-kernel@vger.kernel.org, meatuni001@gmail.com, stable@vger.kernel.org Subject: [PATCH 05/13] platform/x86: hp-bioscfg: fix off-by-one heap OOB write in audit_log_entries_show Date: Mon, 3 Aug 2026 19:30:28 +0500 Message-ID: <20260803143037.93105-6-meatuni001@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260803143037.93105-1-meatuni001@gmail.com> References: <20260803143037.93105-1-meatuni001@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit The per-iteration guard in audit_log_entries_show() is: if (ret < 0 || (LOG_ENTRY_SIZE * i) > PAGE_SIZE) break; ... memcpy(buf, audit_log_buffer, LOG_ENTRY_SIZE); buf += LOG_ENTRY_SIZE; At i == 256 (PAGE_SIZE / LOG_ENTRY_SIZE), LOG_ENTRY_SIZE * i equals PAGE_SIZE exactly, which is not ">" PAGE_SIZE, so the loop does not break and instead writes another LOG_ENTRY_SIZE (16) bytes starting at offset 4096 of the page-sized sysfs output buffer, one entry past its end. This needs the BIOS to report more than 256 audit log entries, which already exceeds this driver's own documented LOG_MAX_ENTRIES of 254, so it requires a non-compliant or corrupted firmware value rather than the roughly 85 million entries an unrelated integer-overflow read of this code might suggest. Fix by checking the bound against the offset the write is about to reach, (i + 1), instead of the offset already written. Fixes: 63e8f906e94e ("platform/x86: hp-bioscfg: surestart-attributes") Cc: stable@vger.kernel.org Signed-off-by: Muhammad Bilal --- drivers/platform/x86/hp/hp-bioscfg/surestart-attributes.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/platform/x86/hp/hp-bioscfg/surestart-attributes.c b/drivers/platform/x86/hp/hp-bioscfg/surestart-attributes.c index b57e42f29282..6b63fdb84606 100644 --- a/drivers/platform/x86/hp/hp-bioscfg/surestart-attributes.c +++ b/drivers/platform/x86/hp/hp-bioscfg/surestart-attributes.c @@ -90,7 +90,7 @@ static ssize_t audit_log_entries_show(struct kobject *kobj, HPWMI_SURESTART, audit_log_buffer, 1, 128); - if (ret < 0 || (LOG_ENTRY_SIZE * i) > PAGE_SIZE) { + if (ret < 0 || (LOG_ENTRY_SIZE * (i + 1)) > PAGE_SIZE) { /* * Encountered a failure while reading * individual logs. Only a partial list of -- 2.55.0