diff options
| author | Johannes Berg | 2026-02-09 19:12:20 +0100 |
|---|---|---|
| committer | Sasha Levin | 2026-03-04 07:20:39 -0500 |
| commit | eddbc75f511edbcca5aeadc934d37a14b5932e8b (patch) | |
| tree | 799f0ec8cb7de7758380607ce4524c75e13bb0ad /net | |
| parent | 5195b10c34b8993194ad12ad7d8f54d861be084b (diff) | |
wifi: cfg80211: wext: fix IGTK key ID off-by-one
[ Upstream commit c8d7f21ead727485ebf965e2b4d42d4a4f0840f6 ]
The IGTK key ID must be 4 or 5, but the code checks against
key ID + 1, so must check against 5/6 rather than 4/5. Fix
that.
Reported-by: Jouni Malinen <j@w1.fi>
Fixes: 08645126dd24 ("cfg80211: implement wext key handling")
Link: https://patch.msgid.link/20260209181220.362205-2-johannes@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Diffstat (limited to 'net')
| -rw-r--r-- | net/wireless/wext-compat.c | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/net/wireless/wext-compat.c b/net/wireless/wext-compat.c index ddf340bfa07a..2fec3606f847 100644 --- a/net/wireless/wext-compat.c +++ b/net/wireless/wext-compat.c @@ -724,7 +724,7 @@ static int cfg80211_wext_siwencodeext(struct net_device *dev, idx = erq->flags & IW_ENCODE_INDEX; if (cipher == WLAN_CIPHER_SUITE_AES_CMAC) { - if (idx < 4 || idx > 5) { + if (idx < 5 || idx > 6) { idx = wdev->wext.default_mgmt_key; if (idx < 0) return -EINVAL; |
