package/wpa_supplicant: add upstream 2020-2 security fix
authorPeter Korsgaard <peter@korsgaard.com>
Fri, 5 Feb 2021 12:13:29 +0000 (13:13 +0100)
committerYann E. MORIN <yann.morin.1998@free.fr>
Fri, 5 Feb 2021 12:42:07 +0000 (13:42 +0100)
commit74c854bd518be67719872a9ceb2336a149458deb
tree21a83d605f211d9149a1b6bab34f8d230a7a2306
parent6490a11018e71d8200f74af581c0a65b1612085a
package/wpa_supplicant: add upstream 2020-2 security fix

Fixes the following security issue:

 - wpa_supplicant P2P group information processing vulnerability (no CVE yet)

   A vulnerability was discovered in how wpa_supplicant processing P2P
   (Wi-Fi Direct) group information from active group owners.  The actual
   parsing of that information validates field lengths appropriately, but
   processing of the parsed information misses a length check when storing a
   copy of the secondary device types.  This can result in writing attacker
   controlled data into the peer entry after the area assigned for the
   secondary device type.  The overflow can result in corrupting pointers
   for heap allocations.  This can result in an attacker within radio range
   of the device running P2P discovery being able to cause unexpected
   behavior, including termination of the wpa_supplicant process and
   potentially arbitrary code execution.

For more details, see the advisory:
https://w1.fi/security/2020-2/wpa_supplicant-p2p-group-info-processing-vulnerability.txt

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
[yann.morin.1998@free.fr: keep _PATCH near _VERSION and _SITE]
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
package/wpa_supplicant/wpa_supplicant.hash
package/wpa_supplicant/wpa_supplicant.mk