diff mbox series

[v2] WPA: Add workaround for APs with byte-swapped IGTK KeyID

Message ID 0a9bff357a40461c9b755e8c96af061f@BJMBX02.spreadtrum.com
State New
Headers show
Series [v2] WPA: Add workaround for APs with byte-swapped IGTK KeyID | expand

Commit Message

Chao Meng Aug. 25, 2026, 2:19 a.m. UTC
From: Chao Meng <chao.meng@unisoc.com>
Date: Tue, 25 Aug 2026 10:16:27 +0800
Subject: [PATCH] WPA: Add workaround for APs with byte-swapped IGTK KeyID

Some deployed APs with broken PMF implementations send IGTK KDE with
byte-swapped KeyID values (e.g., 0x0400 instead of 0x0004), causing the
keyidx > 4095 validation to reject the IGTK and force a disconnection.

Add a workaround that detects this case by checking whether the low byte
of the KeyID is a valid key index (4 or 5). If so, use the corrected
value and continue without disconnecting, logging an informational
message instead of a warning.

Signed-off-by: Chao Meng <chao.meng@unisoc.com>
---
 src/rsn_supp/wpa.c | 27 ++++++++++++++++++++++++---
 1 file changed, 24 insertions(+), 3 deletions(-)

--
2.21.0.windows.1
diff mbox series

Patch

diff --git a/src/rsn_supp/wpa.c b/src/rsn_supp/wpa.c
index 24fa9a781..4e5d3065b 100644
--- a/src/rsn_supp/wpa.c
+++ b/src/rsn_supp/wpa.c
@@ -1727,9 +1727,30 @@  static int wpa_supplicant_install_igtk(struct wpa_sm *sm,
 keyidx, MAC2STR(igtk->pn));
 wpa_hexdump_key(MSG_DEBUG, "WPA: IGTK", igtk->igtk, len);
 if (keyidx > 4095) {
-wpa_msg(sm->ctx->msg_ctx, MSG_WARNING,
-"WPA: Invalid IGTK KeyID %d", keyidx);
-return -1;
+int masked = keyidx & 0xFF;
+if (masked == 4 || masked == 5) {
+/* Assume the AP has broken PMF implementation since it
+ * seems to have swapped the KeyID bytes. The AP cannot
+ * be trusted to implement BIP correctly or provide a
+ * valid IGTK, so do not try to configure this key with
+ * swapped KeyID bytes. Instead, continue without
+ * configuring the IGTK so that the driver can drop any
+ * received group-addressed robust management frames due
+ * to missing keys.
+ *
+ * Normally, this error behavior would result in us
+ * disconnecting, but there are number of deployed APs
+ * with this broken behavior, so as an interoperability
+ * workaround, allow the connection to proceed. */
+wpa_msg(sm->ctx->msg_ctx, MSG_INFO,
+"WPA: Workaround for non-compliant AP: corrected IGTK KeyID %d to %d",
+keyidx, masked);
+keyidx = masked;
+} else {
+wpa_msg(sm->ctx->msg_ctx, MSG_WARNING,
+"WPA: Invalid IGTK KeyID %d", keyidx);
+return -1;
+}
 }
 if (wpa_sm_set_key(sm, -1, wpa_cipher_to_alg(sm->mgmt_group_cipher),
    broadcast_ether_addr,