]> git.ipfire.org Git - thirdparty/hostap.git/commit
SAE: Check for invalid Rejected Groups element length explicitly on STA
authorJouni Malinen <j@w1.fi>
Tue, 9 Jul 2024 20:33:38 +0000 (23:33 +0300)
committerJouni Malinen <j@w1.fi>
Tue, 9 Jul 2024 20:34:21 +0000 (23:34 +0300)
commit593a7c2f8c93edd6b552f2d42e28164464b4e6ff
tree5172cd06d41e3b687e4efeda706ed0eb3bed089d
parent5f98c853e49b884acbb1fd43e70d954fb3aeec80
SAE: Check for invalid Rejected Groups element length explicitly on STA

Instead of practically ignoring an odd octet at the end of the element,
check for such invalid case explicitly. This is needed to avoid a
potential group downgrade attack.

Fixes: 444d76f74f65 ("SAE: Check that peer's rejected groups are not enabled")
Signed-off-by: Jouni Malinen <j@w1.fi>
wpa_supplicant/sme.c