|
@@ -866,11 +866,23 @@ eap_pwd_process(struct eap_sm *sm, void *priv, struct eap_method_ret *ret,
|
|
|
* if it's the first fragment there'll be a length field
|
|
|
*/
|
|
|
if (EAP_PWD_GET_LENGTH_BIT(lm_exch)) {
|
|
|
+ if (len < 2) {
|
|
|
+ wpa_printf(MSG_DEBUG,
|
|
|
+ "EAP-pwd: Frame too short to contain Total-Length field");
|
|
|
+ ret->ignore = TRUE;
|
|
|
+ return NULL;
|
|
|
+ }
|
|
|
tot_len = WPA_GET_BE16(pos);
|
|
|
wpa_printf(MSG_DEBUG, "EAP-pwd: Incoming fragments whose "
|
|
|
"total length = %d", tot_len);
|
|
|
if (tot_len > 15000)
|
|
|
return NULL;
|
|
|
+ if (data->inbuf) {
|
|
|
+ wpa_printf(MSG_DEBUG,
|
|
|
+ "EAP-pwd: Unexpected new fragment start when previous fragment is still in use");
|
|
|
+ ret->ignore = TRUE;
|
|
|
+ return NULL;
|
|
|
+ }
|
|
|
data->inbuf = wpabuf_alloc(tot_len);
|
|
|
if (data->inbuf == NULL) {
|
|
|
wpa_printf(MSG_INFO, "Out of memory to buffer "
|