diff mbox series

[v3] WPA: Add workaround for APs with byte-swapped IGTK KeyID

Message ID 20260825072533.2324-1-chao.meng@unisoc.com
State New
Headers show
Series [v3] WPA: Add workaround for APs with byte-swapped IGTK KeyID | expand

Commit Message

Chao Meng Aug. 25, 2026, 7:25 a.m. UTC
Some deployed APs with broken PMF implementations send IGTK KDE with
byte-swapped KeyID values (e.g., 0x0400 instead of 0x0004), causing the
keyidx > 4095 validation to reject the IGTK and force a disconnection.

Add a workaround that detects this case by checking whether the low byte
of the KeyID is a valid key index (4 or 5). If so, use the corrected
value and continue without disconnecting, logging an informational
message instead of a warning.

Signed-off-by: Chao Meng <chao.meng@unisoc.com>
---
 src/rsn_supp/wpa.c | 27 ++++++++++++++++++++++++---
 1 file changed, 24 insertions(+), 3 deletions(-)

--
2.21.0.windows.1
diff mbox series

Patch

diff --git a/src/rsn_supp/wpa.c b/src/rsn_supp/wpa.c
index 24fa9a781..4e5d3065b 100644
--- a/src/rsn_supp/wpa.c
+++ b/src/rsn_supp/wpa.c
@@ -1727,9 +1727,30 @@  static int wpa_supplicant_install_igtk(struct wpa_sm *sm,
                keyidx, MAC2STR(igtk->pn));
        wpa_hexdump_key(MSG_DEBUG, "WPA: IGTK", igtk->igtk, len);
        if (keyidx > 4095) {
-               wpa_msg(sm->ctx->msg_ctx, MSG_WARNING,
-                       "WPA: Invalid IGTK KeyID %d", keyidx);
-               return -1;
+               int masked = keyidx & 0xFF;
+               if (masked == 4 || masked == 5) {
+                       /* Assume the AP has broken PMF implementation since it
+                        * seems to have swapped the KeyID bytes. The AP cannot
+                        * be trusted to implement BIP correctly or provide a
+                        * valid IGTK, so do not try to configure this key with
+                        * swapped KeyID bytes. Instead, continue without
+                        * configuring the IGTK so that the driver can drop any
+                        * received group-addressed robust management frames due
+                        * to missing keys.
+                        *
+                        * Normally, this error behavior would result in us
+                        * disconnecting, but there are number of deployed APs
+                        * with this broken behavior, so as an interoperability
+                        * workaround, allow the connection to proceed. */
+                       wpa_msg(sm->ctx->msg_ctx, MSG_INFO,
+                               "WPA: Workaround for non-compliant AP: corrected IGTK KeyID %d to %d",
+                               keyidx, masked);
+                       keyidx = masked;
+               } else {
+                       wpa_msg(sm->ctx->msg_ctx, MSG_WARNING,
+                               "WPA: Invalid IGTK KeyID %d", keyidx);
+                       return -1;
+               }
        }
        if (wpa_sm_set_key(sm, -1, wpa_cipher_to_alg(sm->mgmt_group_cipher),
                           broadcast_ether_addr,