2010-03-29 05:31:12

by Jouni Malinen

[permalink] [raw]
Subject: [PATCH] mac80211: Fix robust management frame handling (MFP)

Commit e34e09401ee9888dd662b2fca5d607794a56daf2 incorrectly removed
use of ieee80211_has_protected() from the management frame case and in
practice, made this validation drop all Action frames when MFP is
enabled. This should have only been done for frames with Protected
field set to zero.

Signed-off-by: Jouni Malinen <[email protected]>
Cc: [email protected]

---
net/mac80211/rx.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)

--- wireless-testing.orig/net/mac80211/rx.c 2010-03-28 22:14:33.000000000 -0700
+++ wireless-testing/net/mac80211/rx.c 2010-03-28 22:26:33.000000000 -0700
@@ -1404,7 +1404,8 @@ ieee80211_drop_unencrypted_mgmt(struct i
return res;

if (rx->sta && test_sta_flags(rx->sta, WLAN_STA_MFP)) {
- if (unlikely(ieee80211_is_unicast_robust_mgmt_frame(rx->skb) &&
+ if (unlikely(!ieee80211_has_protected(fc) &&
+ ieee80211_is_unicast_robust_mgmt_frame(rx->skb) &&
rx->key))
return -EACCES;
/* BIP does not use Protected field, so need to check MMIE */

--
Jouni Malinen PGP id EFC895FA