mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH ath-next] wifi: ath11k: fix leak in ath11k_service_ready_ext_event()
@ 2026-07-27 23:39 Jeff Johnson
  2026-07-29  9:05 ` Baochen Qiang
                   ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: Jeff Johnson @ 2026-07-27 23:39 UTC (permalink / raw)
  To: Jeff Johnson; +Cc: ath11k, linux-wireless, linux-kernel, Jeff Johnson

Currently, during ath11k_service_ready_ext_event() processing,
svc_rdy_ext.mac_phy_caps can be allocated during TLV parsing. This is a
temporary allocation that is freed on the success path, but not on the
error path. If parsing succeeds far enough to allocate mac_phy_caps and
then fails on a later TLV, the allocation leaks. So free the allocation
on the error path.

Compile tested only.

Fixes: 5b90fc760db5 ("ath11k: fix wmi service ready ext tlv parsing")
Assisted-by: Claude:claude-sonnet-4-6
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
---
 drivers/net/wireless/ath/ath11k/wmi.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/net/wireless/ath/ath11k/wmi.c b/drivers/net/wireless/ath/ath11k/wmi.c
index 2d2c6d7a4a3b..b2861c879618 100644
--- a/drivers/net/wireless/ath/ath11k/wmi.c
+++ b/drivers/net/wireless/ath/ath11k/wmi.c
@@ -5124,6 +5124,7 @@ static int ath11k_service_ready_ext_event(struct ath11k_base *ab,
 	return 0;
 
 err:
+	kfree(svc_rdy_ext.mac_phy_caps);
 	ath11k_wmi_free_dbring_caps(ab);
 	return ret;
 }

---
base-commit: 189721a4afa1804315e7dcfca9ca0539c7b1d7af
change-id: 20260720-ath11k_service_ready_ext_event-memleak-fbf4abe230f3


^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH ath-next] wifi: ath11k: fix leak in ath11k_service_ready_ext_event()
  2026-07-27 23:39 [PATCH ath-next] wifi: ath11k: fix leak in ath11k_service_ready_ext_event() Jeff Johnson
@ 2026-07-29  9:05 ` Baochen Qiang
  2026-07-30  9:35 ` Rameshkumar Sundaram
  2026-07-31 14:41 ` Jeff Johnson
  2 siblings, 0 replies; 4+ messages in thread
From: Baochen Qiang @ 2026-07-29  9:05 UTC (permalink / raw)
  To: Jeff Johnson, Jeff Johnson; +Cc: ath11k, linux-wireless, linux-kernel



On 7/28/2026 7:39 AM, Jeff Johnson wrote:
> Currently, during ath11k_service_ready_ext_event() processing,
> svc_rdy_ext.mac_phy_caps can be allocated during TLV parsing. This is a
> temporary allocation that is freed on the success path, but not on the
> error path. If parsing succeeds far enough to allocate mac_phy_caps and
> then fails on a later TLV, the allocation leaks. So free the allocation
> on the error path.
> 
> Compile tested only.
> 
> Fixes: 5b90fc760db5 ("ath11k: fix wmi service ready ext tlv parsing")
> Assisted-by: Claude:claude-sonnet-4-6
> Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>

Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH ath-next] wifi: ath11k: fix leak in ath11k_service_ready_ext_event()
  2026-07-27 23:39 [PATCH ath-next] wifi: ath11k: fix leak in ath11k_service_ready_ext_event() Jeff Johnson
  2026-07-29  9:05 ` Baochen Qiang
@ 2026-07-30  9:35 ` Rameshkumar Sundaram
  2026-07-31 14:41 ` Jeff Johnson
  2 siblings, 0 replies; 4+ messages in thread
From: Rameshkumar Sundaram @ 2026-07-30  9:35 UTC (permalink / raw)
  To: Jeff Johnson, Jeff Johnson; +Cc: ath11k, linux-wireless, linux-kernel

On 7/28/2026 5:09 AM, Jeff Johnson wrote:
> Currently, during ath11k_service_ready_ext_event() processing,
> svc_rdy_ext.mac_phy_caps can be allocated during TLV parsing. This is a
> temporary allocation that is freed on the success path, but not on the
> error path. If parsing succeeds far enough to allocate mac_phy_caps and
> then fails on a later TLV, the allocation leaks. So free the allocation
> on the error path.
> 
> Compile tested only.
> 
> Fixes: 5b90fc760db5 ("ath11k: fix wmi service ready ext tlv parsing")
> Assisted-by: Claude:claude-sonnet-4-6
> Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com>

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH ath-next] wifi: ath11k: fix leak in ath11k_service_ready_ext_event()
  2026-07-27 23:39 [PATCH ath-next] wifi: ath11k: fix leak in ath11k_service_ready_ext_event() Jeff Johnson
  2026-07-29  9:05 ` Baochen Qiang
  2026-07-30  9:35 ` Rameshkumar Sundaram
@ 2026-07-31 14:41 ` Jeff Johnson
  2 siblings, 0 replies; 4+ messages in thread
From: Jeff Johnson @ 2026-07-31 14:41 UTC (permalink / raw)
  To: Jeff Johnson, Jeff Johnson; +Cc: ath11k, linux-wireless, linux-kernel


On Mon, 27 Jul 2026 16:39:41 -0700, Jeff Johnson wrote:
> Currently, during ath11k_service_ready_ext_event() processing,
> svc_rdy_ext.mac_phy_caps can be allocated during TLV parsing. This is a
> temporary allocation that is freed on the success path, but not on the
> error path. If parsing succeeds far enough to allocate mac_phy_caps and
> then fails on a later TLV, the allocation leaks. So free the allocation
> on the error path.
> 
> [...]

Applied, thanks!

[1/1] wifi: ath11k: fix leak in ath11k_service_ready_ext_event()
      commit: 0293be2212d319d59589082461abf2a9b626cd1c

Best regards,
-- 
Jeff Johnson <jeff.johnson@oss.qualcomm.com>


^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-07-31 14:41 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-07-27 23:39 [PATCH ath-next] wifi: ath11k: fix leak in ath11k_service_ready_ext_event() Jeff Johnson
2026-07-29  9:05 ` Baochen Qiang
2026-07-30  9:35 ` Rameshkumar Sundaram
2026-07-31 14:41 ` Jeff Johnson

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®