From: Felix Fietkau Date: Fri, 10 Jul 2026 11:58:10 +0000 (+0200) Subject: hostapd: ucode: fix per-station PSK list parsing in sta_auth X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=f3ff33c8a91854d7beee075337c8816a48db16b3;p=thirdparty%2Fopenwrt.git hostapd: ucode: fix per-station PSK list parsing in sta_auth Two defects handling the psk array returned by an auth handler: strlen() ran before the string was validated (strlen(NULL) on a non-string entry), and the hex-PMK branch tested the array length instead of the entry length. A 64-character passphrase therefore reached the passphrase branch and its memcpy of str_len + 1 overflowed passphrase[MAX_PASSPHRASE_LEN + 1] by one byte. Validate the type first and branch on the string length. Signed-off-by: Felix Fietkau --- diff --git a/package/network/services/hostapd/src/src/ap/ucode.c b/package/network/services/hostapd/src/src/ap/ucode.c index 8af8d5cfdea..5e16293d402 100644 --- a/package/network/services/hostapd/src/src/ap/ucode.c +++ b/package/network/services/hostapd/src/src/ap/ucode.c @@ -863,13 +863,15 @@ int hostapd_ucode_sta_auth(struct hostapd_data *hapd, struct sta_info *sta) size_t str_len; cur_psk = ucv_array_get(cur, i); + if (ucv_type(cur_psk) != UC_STRING) + continue; str = ucv_string_get(cur_psk); str_len = strlen(str); - if (!str || str_len < 8 || str_len > 64) + if (str_len < 8 || str_len > 64) continue; p = os_zalloc(sizeof(*p)); - if (len == 64) { + if (str_len == 64) { if (hexstr2bin(str, p->psk, PMK_LEN) < 0) { free(p); continue;