Re: [PATCH net] mac80211: reject ToDS broadcast data frames

2017-04-20 Thread David Miller
From: Johannes Berg Date: Thu, 20 Apr 2017 21:32:16 +0200 > From: Johannes Berg > > AP/AP_VLAN modes don't accept any real 802.11 multicast data > frames, but since they do need to accept broadcast management > frames the same is currently permitted for data frames. This > opens a security prob

[PATCH net] mac80211: reject ToDS broadcast data frames

2017-04-20 Thread Johannes Berg
From: Johannes Berg AP/AP_VLAN modes don't accept any real 802.11 multicast data frames, but since they do need to accept broadcast management frames the same is currently permitted for data frames. This opens a security problem because such frames would be decrypted with the GTK, and could even