[PATCH] WPA: Add workaround for APs with byte-swapped IGTK KeyID

孟超 (Chao Meng) Chao.Meng at unisoc.com
Mon Aug 24 00:15:56 PDT 2026


From f551fc3fc2215a4a6280ecd694ee261ed4f6f2dc Mon Sep 17 00:00:00 2001
From: Chao Meng <chao.meng at unisoc.com>
Date: Mon, 24 Aug 2026 15:14:23 +0800
Subject: [PATCH] WPA: Add workaround for APs with byte-swapped IGTK KeyID

Some deployed APs with broken PMF implementations send IGTK KDE with
byte-swapped KeyID values (e.g., 0x0400 instead of 0x0004), causing the
keyidx > 4095 validation to reject the IGTK and force a disconnection.

Add a workaround that detects this case by checking whether the low byte
of the KeyID is a valid key index (4 or 5). If so, use the corrected
value and continue without disconnecting, logging an informational
message instead of a warning.

Signed-off-by: Chao Meng <chao.meng at unisoc.com>
---
 src/rsn_supp/wpa.c | 27 ++++++++++++++++++++++++---
 1 file changed, 24 insertions(+), 3 deletions(-)

diff --git a/src/rsn_supp/wpa.c b/src/rsn_supp/wpa.c
index 24fa9a781..4e5d3065b 100644
--- a/src/rsn_supp/wpa.c
+++ b/src/rsn_supp/wpa.c
@@ -1727,9 +1727,30 @@ static int wpa_supplicant_install_igtk(struct wpa_sm *sm,
 keyidx, MAC2STR(igtk->pn));
 wpa_hexdump_key(MSG_DEBUG, "WPA: IGTK", igtk->igtk, len);
 if (keyidx > 4095) {
-wpa_msg(sm->ctx->msg_ctx, MSG_WARNING,
-"WPA: Invalid IGTK KeyID %d", keyidx);
-return -1;
+int masked = keyidx & 0xFF;
+if (masked == 4 || masked == 5) {
+/* Assume the AP has broken PMF implementation since it
+ * seems to have swapped the KeyID bytes. The AP cannot
+ * be trusted to implement BIP correctly or provide a
+ * valid IGTK, so do not try to configure this key with
+ * swapped KeyID bytes. Instead, continue without
+ * configuring the IGTK so that the driver can drop any
+ * received group-addressed robust management frames due
+ * to missing keys.
+ *
+ * Normally, this error behavior would result in us
+ * disconnecting, but there are number of deployed APs
+ * with this broken behavior, so as an interoperability
+ * workaround, allow the connection to proceed. */
+wpa_msg(sm->ctx->msg_ctx, MSG_INFO,
+"WPA: Workaround for non-compliant AP: corrected IGTK KeyID %d to %d",
+keyidx, masked);
+keyidx = masked;
+} else {
+wpa_msg(sm->ctx->msg_ctx, MSG_WARNING,
+"WPA: Invalid IGTK KeyID %d", keyidx);
+return -1;
+}
 }
 if (wpa_sm_set_key(sm, -1, wpa_cipher_to_alg(sm->mgmt_group_cipher),
    broadcast_ether_addr,
--
________________________________
 This email (including its attachments) is intended only for the person or entity to which it is addressed and may contain information that is privileged, confidential or otherwise protected from disclosure. Unauthorized use, dissemination, distribution or copying of this email or the information herein or taking any action in reliance on the contents of this email or the information herein, by anyone other than the intended recipient, or an employee or agent responsible for delivering the message to the intended recipient, is strictly prohibited. If you are not the intended recipient, please do not read, copy, use or disclose any part of this e-mail to others. Please notify the sender immediately and permanently delete this e-mail and any attachments if you received it in error. Internet communications cannot be guaranteed to be timely, secure, error-free or virus-free. The sender does not accept liability for any errors or omissions.
本邮件及其附件具有保密性质,受法律保护不得泄露,仅发送给本邮件所指特定收件人。严禁非经授权使用、宣传、发布或复制本邮件或其内容。若非该特定收件人,请勿阅读、复制、 使用或披露本邮件的任何内容。若误收本邮件,请从系统中永久性删除本邮件及所有附件,并以回复邮件的方式即刻告知发件人。无法保证互联网通信及时、安全、无误或防毒。发件人对任何错漏均不承担责任。


More information about the Hostap mailing list