diff --git a/external/bsd/wpa/dist/src/ap/drv_callbacks.c b/external/bsd/wpa/dist/src/ap/drv_callbacks.c index a726a6ff87e0..0793881f5b67 100644 --- a/external/bsd/wpa/dist/src/ap/drv_callbacks.c +++ b/external/bsd/wpa/dist/src/ap/drv_callbacks.c @@ -129,6 +129,19 @@ int hostapd_notif_assoc(struct hostapd_data *hapd, const u8 *addr, "hostapd_notif_assoc: Skip event with no address"); return -1; } + + if (is_multicast_ether_addr(addr) || + is_zero_ether_addr(addr) || + os_memcmp(addr, hapd->own_addr, ETH_ALEN) == 0) { + /* Do not process any frames with unexpected/invalid SA so that + * we do not add any state for unexpected STA addresses or end + * up sending out frames to unexpected destination. */ + wpa_printf(MSG_DEBUG, "%s: Invalid SA=" MACSTR + " in received indication - ignore this indication silently", + __func__, MAC2STR(addr)); + return 0; + } + random_add_randomness(addr, ETH_ALEN); hostapd_logger(hapd, addr, HOSTAPD_MODULE_IEEE80211, diff --git a/external/bsd/wpa/dist/src/ap/ieee802_11.c b/external/bsd/wpa/dist/src/ap/ieee802_11.c index f9bb99d98549..940340412485 100644 --- a/external/bsd/wpa/dist/src/ap/ieee802_11.c +++ b/external/bsd/wpa/dist/src/ap/ieee802_11.c @@ -3978,6 +3978,18 @@ int ieee802_11_mgmt(struct hostapd_data *hapd, const u8 *buf, size_t len, fc = le_to_host16(mgmt->frame_control); stype = WLAN_FC_GET_STYPE(fc); + if (is_multicast_ether_addr(mgmt->sa) || + is_zero_ether_addr(mgmt->sa) || + os_memcmp(mgmt->sa, hapd->own_addr, ETH_ALEN) == 0) { + /* Do not process any frames with unexpected/invalid SA so that + * we do not add any state for unexpected STA addresses or end + * up sending out frames to unexpected destination. */ + wpa_printf(MSG_DEBUG, "MGMT: Invalid SA=" MACSTR + " in received frame - ignore this frame silently", + MAC2STR(mgmt->sa)); + return 0; + } + if (stype == WLAN_FC_STYPE_BEACON) { handle_beacon(hapd, mgmt, len, fi); return 1;