From 6b8f566498156981d01c39a4198a50949cd3a6f1 Mon Sep 17 00:00:00 2001 From: James Prestwood Date: Wed, 16 Oct 2019 16:43:04 -0700 Subject: [PATCH] ie: reorder ie_parse_osen to fix uninitialized value RSNE_ADVANCE could result in a jump to the done label where info would be copied without being initialized. --- src/ie.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/src/ie.c b/src/ie.c index 4bc56589..ba5210c8 100644 --- a/src/ie.c +++ b/src/ie.c @@ -827,13 +827,13 @@ int ie_parse_osen(struct ie_tlv_iter *iter, struct ie_rsn_info *out_info) if (!is_ie_wfa_ie(iter->data, iter->len, IE_WFA_OI_OSEN)) return -EPROTOTYPE; - RSNE_ADVANCE(data, len, 4); - memset(&info, 0, sizeof(info)); info.group_cipher = IE_RSN_CIPHER_SUITE_NO_GROUP_TRAFFIC; info.pairwise_ciphers = IE_RSN_CIPHER_SUITE_CCMP; info.akm_suites = IE_RSN_AKM_SUITE_8021X; + RSNE_ADVANCE(data, len, 4); + if (parse_ciphers(data, len, ie_parse_osen_akm_suite, &info) < 0) return -EBADMSG;