[PATCH v4 8/9] platform/x86: hp-bioscfg: NUL-terminate the SPM auth token

From: Muhammad Bilal

Date: Fri Oct 02 2026 - 15:16:41 EST


auth_token_store() copies the token with kmemdup(), which does not NUL
terminate it, but hp_calculate_security_buffer() and
hp_populate_security_buffer() treat it as a C string and read past the
allocation.

A lone newline (echo > auth_token) is worse: kmemdup() of 0 bytes
returns ZERO_SIZE_PTR, which passes the NULL checks, so a later
attribute write calls strlen() on address 0x10.

Use kmemdup_nul(), which allocates one extra byte for the terminator
and never returns ZERO_SIZE_PTR.

Compile tested only.

Fixes: b2715aa2e135 ("platform/x86: hp-bioscfg: spmobj-attributes")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Muhammad Bilal <meatuni001@xxxxxxxxx>
---
Changes in v4:
- New patch

drivers/platform/x86/hp/hp-bioscfg/spmobj-attributes.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/platform/x86/hp/hp-bioscfg/spmobj-attributes.c b/drivers/platform/x86/hp/hp-bioscfg/spmobj-attributes.c
index f0eb5c445..19f0f9f16 100644
--- a/drivers/platform/x86/hp/hp-bioscfg/spmobj-attributes.c
+++ b/drivers/platform/x86/hp/hp-bioscfg/spmobj-attributes.c
@@ -316,7 +316,7 @@ static ssize_t auth_token_store(struct kobject *kobj,
length--;

/* allocate space and copy current auth token */
- bioscfg_drv.spm_data.auth_token = kmemdup(buf, length, GFP_KERNEL);
+ bioscfg_drv.spm_data.auth_token = kmemdup_nul(buf, length, GFP_KERNEL);
if (!bioscfg_drv.spm_data.auth_token) {
ret = -ENOMEM;
goto exit_token;
--
2.43.0