tnccs-dynamic: Add missing checks for underlying TNCCS instance
In order for the TNCCS instance to get created, `process()` has to be
called first. However, if the client responds to the initial request
with an empty EAP packet, `tls_eap_t` interprets that as acknowledgement
and directly calls `build_pkt()`, which attempts to call `build()` here
and triggers a NULL-pointer dereference. Similarly, `process()` is
skipped if the client sends an EAP packet that has the EAP_TLS|PT_START
flag set.
The `get_pdp_server()` method is called when the EAP-TNC method that
owns this instance is destroyed and would likewise trigger a crash if
e.g. the client never responded and the EAP-TNC instance is destroyed
without `process()` ever being called.
Fixes: f652995b21 ("implemented dynamic detection of TNCCS protocol")
This commit is contained in:
@@ -124,7 +124,7 @@ METHOD(tls_t, process, status_t,
|
|||||||
this->peer_ip, this->transport, this->callback);
|
this->peer_ip, this->transport, this->callback);
|
||||||
if (!tnccs)
|
if (!tnccs)
|
||||||
{
|
{
|
||||||
DBG1(DBG_TNC, "N% protocol not supported", tnccs_type_names, type);
|
DBG1(DBG_TNC, "%N protocol not supported", tnccs_type_names, type);
|
||||||
return FAILED;
|
return FAILED;
|
||||||
}
|
}
|
||||||
tnccs->set_auth_type(tnccs, this->auth_type);
|
tnccs->set_auth_type(tnccs, this->auth_type);
|
||||||
@@ -136,6 +136,11 @@ METHOD(tls_t, process, status_t,
|
|||||||
METHOD(tls_t, build, status_t,
|
METHOD(tls_t, build, status_t,
|
||||||
private_tnccs_dynamic_t *this, void *buf, size_t *buflen, size_t *msglen)
|
private_tnccs_dynamic_t *this, void *buf, size_t *buflen, size_t *msglen)
|
||||||
{
|
{
|
||||||
|
if (!this->tls)
|
||||||
|
{
|
||||||
|
DBG1(DBG_TNC, "no TNCCS protocol detected, unable to respond");
|
||||||
|
return FAILED;
|
||||||
|
}
|
||||||
return this->tls->build(this->tls, buf, buflen, msglen);
|
return this->tls->build(this->tls, buf, buflen, msglen);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -241,6 +246,11 @@ METHOD(tnccs_t, get_pdp_server, chunk_t,
|
|||||||
{
|
{
|
||||||
tnccs_t *tnccs = (tnccs_t*)this->tls;
|
tnccs_t *tnccs = (tnccs_t*)this->tls;
|
||||||
|
|
||||||
|
if (!tnccs)
|
||||||
|
{
|
||||||
|
*port = 0;
|
||||||
|
return chunk_empty;
|
||||||
|
}
|
||||||
return tnccs->get_pdp_server(tnccs, port);
|
return tnccs->get_pdp_server(tnccs, port);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user