Takashi Iwai 23c1bb
From 0dc267b13f3a7e8424a898815dd357211b737330 Mon Sep 17 00:00:00 2001
Takashi Iwai 23c1bb
From: Wen Gong <wgong@codeaurora.org>
Takashi Iwai 23c1bb
Date: Tue, 11 May 2021 20:02:56 +0200
Takashi Iwai 23c1bb
Subject: [PATCH] ath10k: Fix TKIP Michael MIC verification for PCIe
Takashi Iwai 23c1bb
Git-commit: 0dc267b13f3a7e8424a898815dd357211b737330
Takashi Iwai 23c1bb
Git-repo: git://git.kernel.org/pub/scm/linux/kernel/git/jberg/mac80211-next.git
Takashi Iwai 23c1bb
Patch-mainline: Queued in subsystem maintainer repo
Takashi Iwai 23c1bb
References: CVE-2020-26141 bsc#1185863 bsc#1185987
Takashi Iwai 23c1bb
Takashi Iwai 23c1bb
TKIP Michael MIC was not verified properly for PCIe cases since the
Takashi Iwai 23c1bb
validation steps in ieee80211_rx_h_michael_mic_verify() in mac80211 did
Takashi Iwai 23c1bb
not get fully executed due to unexpected flag values in
Takashi Iwai 23c1bb
ieee80211_rx_status.
Takashi Iwai 23c1bb
Takashi Iwai 23c1bb
Fix this by setting the flags property to meet mac80211 expectations for
Takashi Iwai 23c1bb
performing Michael MIC validation there. This fixes CVE-2020-26141. It
Takashi Iwai 23c1bb
does the same as ath10k_htt_rx_proc_rx_ind_hl() for SDIO which passed
Takashi Iwai 23c1bb
MIC verification case. This applies only to QCA6174/QCA9377 PCIe.
Takashi Iwai 23c1bb
Takashi Iwai 23c1bb
Tested-on: QCA6174 hw3.2 PCI WLAN.RM.4.4.1-00110-QCARMSWP-1
Takashi Iwai 23c1bb
Takashi Iwai 23c1bb
Cc: stable@vger.kernel.org
Takashi Iwai 23c1bb
Signed-off-by: Wen Gong <wgong@codeaurora.org>
Takashi Iwai 23c1bb
Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
Takashi Iwai 23c1bb
Link: https://lore.kernel.org/r/20210511200110.c3f1d42c6746.I795593fcaae941c471425b8c7d5f7bb185d29142@changeid
Takashi Iwai 23c1bb
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Takashi Iwai 23c1bb
Acked-by: Takashi Iwai <tiwai@suse.de>
Takashi Iwai 23c1bb
Takashi Iwai 23c1bb
---
Takashi Iwai 23c1bb
 drivers/net/wireless/ath/ath10k/htt_rx.c |    8 ++++++++
Takashi Iwai 23c1bb
 1 file changed, 8 insertions(+)
Takashi Iwai 23c1bb
Takashi Iwai 23c1bb
--- a/drivers/net/wireless/ath/ath10k/htt_rx.c
Takashi Iwai 23c1bb
+++ b/drivers/net/wireless/ath/ath10k/htt_rx.c
Takashi Iwai 23c1bb
@@ -1425,6 +1425,10 @@ static void ath10k_htt_rx_h_mpdu(struct
Takashi Iwai 23c1bb
 		}
Takashi Iwai 23c1bb
 
Takashi Iwai 23c1bb
 		ath10k_htt_rx_h_csum_offload(msdu);
Takashi Iwai 23c1bb
+
Takashi Iwai 23c1bb
+		if (frag && enctype == HTT_RX_MPDU_ENCRYPT_TKIP_WPA)
Takashi Iwai 23c1bb
+			status->flag &= ~RX_FLAG_MMIC_STRIPPED;
Takashi Iwai 23c1bb
+
Takashi Iwai 23c1bb
 		ath10k_htt_rx_h_undecap(ar, msdu, status, first_hdr, enctype,
Takashi Iwai 23c1bb
 					is_decrypted);
Takashi Iwai 23c1bb
 
Takashi Iwai 23c1bb
@@ -1439,6 +1443,10 @@ static void ath10k_htt_rx_h_mpdu(struct
Takashi Iwai 23c1bb
 
Takashi Iwai 23c1bb
 		hdr = (void *)msdu->data;
Takashi Iwai 23c1bb
 		hdr->frame_control &= ~__cpu_to_le16(IEEE80211_FCTL_PROTECTED);
Takashi Iwai 23c1bb
+
Takashi Iwai 23c1bb
+		if (frag && enctype == HTT_RX_MPDU_ENCRYPT_TKIP_WPA)
Takashi Iwai 23c1bb
+			status->flag &= ~RX_FLAG_IV_STRIPPED &
Takashi Iwai 23c1bb
+					~RX_FLAG_MMIC_STRIPPED;
Takashi Iwai 23c1bb
 	}
Takashi Iwai 23c1bb
 }
Takashi Iwai 23c1bb