From 594c30b7ec92a37e4178bf3cbfd3504cb343ce18 Mon Sep 17 00:00:00 2001 From: Krupali Dhanvijay Date: Mon, 13 Oct 2025 10:57:26 +0530 Subject: [PATCH] qcacld-3.0: Consider intersected AKM for association MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Currently host overwrites crypto AKM with candidate AP’s AKM. To choose the most secure AKM, host do sort of AKMs properly based on security to use for association and can choose the AKM which station do not advertise and results in Assoc failure. To fix this, consider intersection of crypto and candidate AP’s AKM for association instead of AKMs directly from AP config. CRs-Fixed: 4320132 Change-Id: Id1813fc9f7fe76ff5ae9daf4da051067bddfdce1 --- core/sme/src/csr/csr_util.c | 22 +++++++++++++++++++--- 1 file changed, 19 insertions(+), 3 deletions(-) diff --git a/core/sme/src/csr/csr_util.c b/core/sme/src/csr/csr_util.c index f8c2f48b711c..ecd857bcd604 100644 --- a/core/sme/src/csr/csr_util.c +++ b/core/sme/src/csr/csr_util.c @@ -1,6 +1,6 @@ /* * Copyright (c) 2011-2021 The Linux Foundation. All rights reserved. - * Copyright (c) 2021-2024 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -2451,6 +2451,7 @@ static void csr_update_key_mgmt_crypto_param(struct wlan_objmgr_vdev *vdev, { int32_t key_mgmt = 0; int32_t neg_akm; + int32_t ap_akm = 0; uint8_t i; neg_akm = wlan_crypto_get_param(vdev, WLAN_CRYPTO_PARAM_KEY_MGMT); @@ -2460,9 +2461,16 @@ static void csr_update_key_mgmt_crypto_param(struct wlan_objmgr_vdev *vdev, } for (i = 0; i < ap_rsn.akm_suite_cnt; i++) - SET_PARAM(neg_akm, + SET_PARAM(ap_akm, wlan_crypto_rsn_suite_to_keymgmt(ap_rsn.akm_suite[i])); + /* Intersect crypto AKM and candidate AP's AKM */ + neg_akm &= ap_akm; + if (neg_akm <= 0) { + sme_err("Invalid AKM suite"); + return; + } + /* * As there can be multiple AKM present select the most secured AKM * present @@ -2531,6 +2539,7 @@ static void csr_update_ucast_cipher_crypto_param(struct wlan_objmgr_vdev *vdev, { int32_t ucastcipherset = 0; int32_t neg_ucastcipher; + int32_t ap_ucastcipher = 0; uint8_t i; neg_ucastcipher = wlan_crypto_get_param(vdev, @@ -2541,9 +2550,16 @@ static void csr_update_ucast_cipher_crypto_param(struct wlan_objmgr_vdev *vdev, } for (i = 0; i < ap_rsn.pwise_cipher_suite_count; i++) - SET_PARAM(neg_ucastcipher, + SET_PARAM(ap_ucastcipher, wlan_crypto_rsn_suite_to_cipher(ap_rsn.pwise_cipher_suites[i])); + /* Intersect crypto cipherset and candidate AP's cipherset */ + neg_ucastcipher &= ap_ucastcipher; + if (neg_ucastcipher <= 0) { + sme_err("Invalid unicast cipherset"); + return; + } + /* * As there can be multiple ucastcipher present select the most secured * ucastcipher present.