hostapd: ucode: fix per-station PSK list parsing in sta_auth
Two defects handling the psk array returned by an auth handler: strlen() ran before the string was validated (strlen(NULL) on a non-string entry), and the hex-PMK branch tested the array length instead of the entry length. A 64-character passphrase therefore reached the passphrase branch and its memcpy of str_len + 1 overflowed passphrase[MAX_PASSPHRASE_LEN + 1] by one byte. Validate the type first and branch on the string length. Signed-off-by: Felix Fietkau <nbd@nbd.name>
This commit is contained in:
parent
eb5ccabf0e
commit
f3ff33c8a9
1 changed files with 4 additions and 2 deletions
|
|
@ -863,13 +863,15 @@ int hostapd_ucode_sta_auth(struct hostapd_data *hapd, struct sta_info *sta)
|
||||||
size_t str_len;
|
size_t str_len;
|
||||||
|
|
||||||
cur_psk = ucv_array_get(cur, i);
|
cur_psk = ucv_array_get(cur, i);
|
||||||
|
if (ucv_type(cur_psk) != UC_STRING)
|
||||||
|
continue;
|
||||||
str = ucv_string_get(cur_psk);
|
str = ucv_string_get(cur_psk);
|
||||||
str_len = strlen(str);
|
str_len = strlen(str);
|
||||||
if (!str || str_len < 8 || str_len > 64)
|
if (str_len < 8 || str_len > 64)
|
||||||
continue;
|
continue;
|
||||||
|
|
||||||
p = os_zalloc(sizeof(*p));
|
p = os_zalloc(sizeof(*p));
|
||||||
if (len == 64) {
|
if (str_len == 64) {
|
||||||
if (hexstr2bin(str, p->psk, PMK_LEN) < 0) {
|
if (hexstr2bin(str, p->psk, PMK_LEN) < 0) {
|
||||||
free(p);
|
free(p);
|
||||||
continue;
|
continue;
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue