Two defects handling the psk array returned by an auth handler: strlen()
ran before the string was validated (strlen(NULL) on a non-string entry),
and the hex-PMK branch tested the array length instead of the entry length.
A 64-character passphrase therefore reached the passphrase branch and its
memcpy of str_len + 1 overflowed passphrase[MAX_PASSPHRASE_LEN + 1] by one
byte. Validate the type first and branch on the string length.
Signed-off-by: Felix Fietkau <nbd@nbd.name>
size_t str_len;
cur_psk = ucv_array_get(cur, i);
+ if (ucv_type(cur_psk) != UC_STRING)
+ continue;
str = ucv_string_get(cur_psk);
str_len = strlen(str);
- if (!str || str_len < 8 || str_len > 64)
+ if (str_len < 8 || str_len > 64)
continue;
p = os_zalloc(sizeof(*p));
- if (len == 64) {
+ if (str_len == 64) {
if (hexstr2bin(str, p->psk, PMK_LEN) < 0) {
free(p);
continue;