From c0b58df382391d917710aaa9c73135d55b52c7e5 Mon Sep 17 00:00:00 2001 From: "tarun.kumar" Date: Fri, 17 Apr 2026 00:34:16 +0530 Subject: [PATCH] fix(wifi) : Fixed some issues found using static analysis --- .../wpa_supplicant/esp_supplicant/src/esp_hostap.c | 5 ++++- components/wpa_supplicant/src/ap/ieee802_11.c | 13 ++++++++++--- 2 files changed, 14 insertions(+), 4 deletions(-) diff --git a/components/wpa_supplicant/esp_supplicant/src/esp_hostap.c b/components/wpa_supplicant/esp_supplicant/src/esp_hostap.c index 207f3dcb2d0..d9f53672c30 100644 --- a/components/wpa_supplicant/esp_supplicant/src/esp_hostap.c +++ b/components/wpa_supplicant/esp_supplicant/src/esp_hostap.c @@ -393,6 +393,7 @@ u16 esp_send_assoc_resp(struct hostapd_data *hapd, const u8 *addr, struct wpabuf *owe_ie = esp_owe_build_assoc_resp_dhie(hapd, addr, &owe_ie_len); if (owe_ie_len <= 0 || !owe_ie) { wpa_printf(MSG_ERROR, "%s : error creating dhie for assoc resp %d ", __func__, owe_ie_len); + wpabuf_free(owe_ie); return WLAN_STATUS_UNSPECIFIED_FAILURE; } esp_wifi_set_appie_internal(WIFI_APPIE_ASSOC_RESP, (uint8_t *)wpabuf_head(owe_ie), owe_ie_len, 0); @@ -497,11 +498,13 @@ bool hostap_new_assoc_sta(struct sta_info *sta, uint8_t *bssid, u8 *wpa_ie, #ifdef CONFIG_OWE_SOFTAP uint8_t owe_enabled = esp_wifi_ap_get_owe_config_internal(); - if (hapd->conf->wpa_key_mgmt & WPA_KEY_MGMT_OWE && + if (status == WLAN_STATUS_SUCCESS && + hapd->conf->wpa_key_mgmt & WPA_KEY_MGMT_OWE && sta->wpa_sm->wpa_key_mgmt == WPA_KEY_MGMT_OWE && owe_dh && owe_enabled) { status = owe_process_assoc_req(hapd, sta, owe_dh, owe_ie_len); if (status != WLAN_STATUS_SUCCESS) { + *reason = wpa_status_to_reason_code(status); wpa_printf(MSG_ERROR, "OWE : Failed to process assoc req status %d", status); return false; } diff --git a/components/wpa_supplicant/src/ap/ieee802_11.c b/components/wpa_supplicant/src/ap/ieee802_11.c index 5e09b8425b3..bb1c0b57ae4 100644 --- a/components/wpa_supplicant/src/ap/ieee802_11.c +++ b/components/wpa_supplicant/src/ap/ieee802_11.c @@ -23,6 +23,7 @@ #ifdef CONFIG_OWE_SOFTAP #include "crypto/crypto.h" #include "ap/wpa_auth_i.h" +#include "esp_owe_i.h" #define OWE_DH_GRP19 19 #endif @@ -817,8 +818,8 @@ uint16_t owe_process_assoc_req(struct hostapd_data *hapd, struct sta_info *sta, return WLAN_STATUS_SUCCESS; } - if (!owe_dh) { - wpa_printf(MSG_ERROR, "OWE: Invalid DH data received"); + if (!owe_dh || owe_dh_len < OWE_DHIE_LEN - 2) { + wpa_printf(MSG_ERROR, "OWE: Invalid DH data received (len=%u)", owe_dh_len); return WLAN_STATUS_UNSPECIFIED_FAILURE; } @@ -930,7 +931,13 @@ uint16_t owe_process_assoc_req(struct hostapd_data *hapd, struct sta_info *sta, sta->owe_pmk_len = SHA256_MAC_LEN; // Add the PMK to the PMKSA cache - wpa_auth_pmksa_add2(hapd->wpa_auth, sta->addr, sta->owe_pmk, sta->owe_pmk_len, pmkid, 0, WPA_KEY_MGMT_OWE, NULL); + if (wpa_auth_pmksa_add2(hapd->wpa_auth, sta->addr, sta->owe_pmk, sta->owe_pmk_len, + pmkid, 0, WPA_KEY_MGMT_OWE, NULL) < 0) { + os_free(sta->owe_pmk); + sta->owe_pmk = NULL; + wpa_printf(MSG_ERROR, "OWE: Failed to add PMKSA cache entry"); + return WLAN_STATUS_UNSPECIFIED_FAILURE; + } // Update the PMKID in the STA's WPA state machine os_memcpy(sta->wpa_sm->pmkid, pmkid, PMKID_LEN);