| Message ID | 20260512131558.18020-1-chung-hsien.hsu@infineon.com |
|---|---|
| Headers | show
Return-Path:
<hostap-bounces+incoming=patchwork.ozlabs.org@lists.infradead.org>
X-Original-To: incoming@patchwork.ozlabs.org
Delivered-To: patchwork-incoming@legolas.ozlabs.org
Authentication-Results: legolas.ozlabs.org;
dkim=pass (2048-bit key;
secure) header.d=lists.infradead.org header.i=@lists.infradead.org
header.a=rsa-sha256 header.s=bombadil.20210309 header.b=CeHZa7F7;
dkim=fail reason="signature verification failed" (1024-bit key;
unprotected) header.d=infineon.com header.i=@infineon.com header.a=rsa-sha256
header.s=IFXMAIL header.b=VrZbcMFd;
dkim-atps=neutral
Authentication-Results: legolas.ozlabs.org;
spf=none (no SPF record) smtp.mailfrom=lists.infradead.org
(client-ip=2607:7c80:54:3::133; helo=bombadil.infradead.org;
envelope-from=hostap-bounces+incoming=patchwork.ozlabs.org@lists.infradead.org;
receiver=patchwork.ozlabs.org)
Received: from bombadil.infradead.org (bombadil.infradead.org
[IPv6:2607:7c80:54:3::133])
(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
key-exchange x25519 server-signature ECDSA (secp384r1) server-digest SHA384)
(No client certificate requested)
by legolas.ozlabs.org (Postfix) with ESMTPS id 4gFHHk0n2Fz1yJ5
for <incoming@patchwork.ozlabs.org>; Tue, 12 May 2026 23:19:30 +1000 (AEST)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=lists.infradead.org; s=bombadil.20210309; h=Sender:
Content-Transfer-Encoding:Content-Type:List-Subscribe:List-Help:List-Post:
List-Archive:List-Unsubscribe:List-Id:MIME-Version:Message-ID:Date:Subject:CC
:To:From:Reply-To:Content-ID:Content-Description:Resent-Date:Resent-From:
Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:In-Reply-To:References:
List-Owner; bh=EB4dSW9+7KDLQMYQdCtkcLasTZLVHjKMo09zVQayhlQ=; b=CeHZa7F7ZjPe/o
yeYAU6LwCxl1FVj14+5ArmVOkAjBg9RQE7oZ0thsRmhsmF42lfMr5v59VQjWZPaa1XX06cI4bA/0a
m8VQtSSNPVAW3cXa3sWaVFHyeVWXkVtapVTOFj1i0HYuRXE6EZCxT/1SmwWPgk1NSsKrm8HK1Loz5
YDHX8k0ZZauVa3EspZg2ySHjPVdHFUS5oSay5zMmEdvHMQIo7J/4IWN5Wq0CLvYtPCbUM2f+mHyRX
BI1a/gL3/fIniXj6uHvBWIdtc+fro7Yf5CG8R7nv4+3de8lf4jvVjcwlGpmWEej64WnAtSqutYUmb
Gn/YhJA/QmCM+2BpBaQQ==;
Received: from localhost ([::1] helo=bombadil.infradead.org)
by bombadil.infradead.org with esmtp (Exim 4.99.1 #2 (Red Hat Linux))
id 1wMmzW-0000000Gnmx-3SNR;
Tue, 12 May 2026 13:17:42 +0000
Received: from smtp11.infineon.com ([2a00:18f0:1e00:4::5])
by bombadil.infradead.org with esmtps (Exim 4.99.1 #2 (Red Hat Linux))
id 1wMmzU-0000000GnlM-1koN
for hostap@lists.infradead.org;
Tue, 12 May 2026 13:17:41 +0000
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple;
d=infineon.com; i=@infineon.com; q=dns/txt; s=IFXMAIL;
t=1778591861; x=1810127861;
h=from:to:cc:subject:date:message-id:mime-version:
content-transfer-encoding;
bh=LoHW3x1Xapbcvd5PB5lGs1j3NzajGWp0bMP4XHXWnRg=;
b=VrZbcMFdYKzF25ImB9zhKrgvr7foGPNQdmci31wZDHmCqD5hbZoPyYpA
7JK++UdeizXHthUOEBtfMjcoVyUnYntmBMyE0AIKHJJi70VB0cwgcjIwD
tH4p6nz5w+YaEseykjJBFIaLwfFRfhiI8a/Ij7KP3hexI3St51odbbqtY
I=;
X-CSE-ConnectionGUID: lrUE6rNyS6mlbH4/VSlVhw==
X-CSE-MsgGUID: SDg4Ok63S+ipa/FG95FSBw==
X-IronPort-AV: E=McAfee;i="6800,10657,11783"; a="142918358"
X-IronPort-AV: E=Sophos;i="6.23,230,1770591600";
d="scan'208";a="142918358"
X-Amp-Result: SKIPPED(no attachment in message)
Received: from unknown (HELO MUCSE803.infineon.com) ([172.23.29.29])
by smtp11.infineon.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384;
12 May 2026 15:17:37 +0200
Received: from MUCSE825.infineon.com (172.23.29.18) by MUCSE803.infineon.com
(172.23.29.29) with Microsoft SMTP Server (version=TLS1_2,
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.37; Tue, 12 May
2026 15:17:35 +0200
Received: from ISCN5CG4472QHC.infineon.com (10.161.6.196) by
MUCSE825.infineon.com (172.23.29.18) with Microsoft SMTP Server
(version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id
15.2.2562.37; Tue, 12 May 2026 15:17:34 +0200
From: Chung-Hsien Hsu <chung-hsien.hsu@infineon.com>
To: <hostap@lists.infradead.org>
CC: Chung-Hsien Hsu <chung-hsien.hsu@infineon.com>
Subject: [PATCH 0/2] RSN: Validate GTK KDE lengths before msg 4/4
Date: Tue, 12 May 2026 21:15:56 +0800
Message-ID: <20260512131558.18020-1-chung-hsien.hsu@infineon.com>
X-Mailer: git-send-email 2.25.1
MIME-Version: 1.0
X-Originating-IP: [10.161.6.196]
X-ClientProxiedBy: MUCSE804.infineon.com (172.23.29.30) To
MUCSE825.infineon.com (172.23.29.18)
X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.9.0 (BSD) ) MR-646709E3
X-CRM114-CacheID: sfid-20260512_061740_777707_66F7A65E
X-CRM114-Status: UNSURE ( 8.40 )
X-CRM114-Notice: Please train this message.
X-Spam-Score: -2.1 (--)
X-Spam-Report: Spam detection software,
running on the system "bombadil.infradead.org",
has NOT identified this incoming email as spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
the administrator of that system for details.
Content preview: Validate GTK KDE lengths in EAPOL-Key message 3/4 before
transmitting
message 4/4. The GTK KDE length is already checked when processing the GTK
for installation. However, that validation is reached only after message
4/4 has been transmitted. This allows a malformed message 3/4 wit [...]
Content analysis details: (-2.1 points, 5.0 required)
pts rule name description
---- ----------------------
--------------------------------------------------
0.0 SPF_HELO_NONE SPF: HELO does not publish an SPF Record
-0.0 SPF_PASS SPF: sender matches SPF record
0.1 DKIM_SIGNED Message has a DKIM or DK signature,
not necessarily valid
-0.1 DKIM_VALID Message has at least one valid DKIM or DK
signature
-0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from
envelope-from domain
-0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from
author's
domain
-1.9 BAYES_00 BODY: Bayes spam probability is 0 to 1%
[score: 0.0000]
-0.0 DMARC_PASS DMARC pass policy
X-BeenThere: hostap@lists.infradead.org
X-Mailman-Version: 2.1.34
Precedence: list
List-Id: <hostap.lists.infradead.org>
List-Unsubscribe: <http://lists.infradead.org/mailman/options/hostap>,
<mailto:hostap-request@lists.infradead.org?subject=unsubscribe>
List-Archive: <http://lists.infradead.org/pipermail/hostap/>
List-Post: <mailto:hostap@lists.infradead.org>
List-Help: <mailto:hostap-request@lists.infradead.org?subject=help>
List-Subscribe: <http://lists.infradead.org/mailman/listinfo/hostap>,
<mailto:hostap-request@lists.infradead.org?subject=subscribe>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Sender: "Hostap" <hostap-bounces@lists.infradead.org>
Errors-To: hostap-bounces+incoming=patchwork.ozlabs.org@lists.infradead.org
|
| Series |
RSN: Validate GTK KDE lengths before msg 4/4
|
expand
|
On Tue, May 12, 2026 at 09:15:56PM +0800, Chung-Hsien Hsu wrote: > Validate GTK KDE lengths in EAPOL-Key message 3/4 before transmitting > message 4/4. > > The GTK KDE length is already checked when processing the GTK for > installation. However, that validation is reached only after message 4/4 > has been transmitted. This allows a malformed message 3/4 with an > invalid GTK KDE length to be acknowledged even though the supplicant > later rejects the GTK and fails the handshake. > > This series splits the early validation into non-MLO and MLO changes. > > Chung-Hsien Hsu (2): > RSN: Reject invalid GTK KDE length in msg 3/4 > RSN: Reject invalid MLO GTK KDE length in msg 3/4 Thanks, applied with some cleanup.