* [PATCH ath-next] wifi: ath11k: fix leak in ath11k_service_ready_ext_event()
@ 2026-07-27 23:39 Jeff Johnson
2026-07-29 9:05 ` Baochen Qiang
` (2 more replies)
0 siblings, 3 replies; 4+ messages in thread
From: Jeff Johnson @ 2026-07-27 23:39 UTC (permalink / raw)
To: Jeff Johnson; +Cc: ath11k, linux-wireless, linux-kernel, Jeff Johnson
Currently, during ath11k_service_ready_ext_event() processing,
svc_rdy_ext.mac_phy_caps can be allocated during TLV parsing. This is a
temporary allocation that is freed on the success path, but not on the
error path. If parsing succeeds far enough to allocate mac_phy_caps and
then fails on a later TLV, the allocation leaks. So free the allocation
on the error path.
Compile tested only.
Fixes: 5b90fc760db5 ("ath11k: fix wmi service ready ext tlv parsing")
Assisted-by: Claude:claude-sonnet-4-6
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
---
drivers/net/wireless/ath/ath11k/wmi.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/net/wireless/ath/ath11k/wmi.c b/drivers/net/wireless/ath/ath11k/wmi.c
index 2d2c6d7a4a3b..b2861c879618 100644
--- a/drivers/net/wireless/ath/ath11k/wmi.c
+++ b/drivers/net/wireless/ath/ath11k/wmi.c
@@ -5124,6 +5124,7 @@ static int ath11k_service_ready_ext_event(struct ath11k_base *ab,
return 0;
err:
+ kfree(svc_rdy_ext.mac_phy_caps);
ath11k_wmi_free_dbring_caps(ab);
return ret;
}
---
base-commit: 189721a4afa1804315e7dcfca9ca0539c7b1d7af
change-id: 20260720-ath11k_service_ready_ext_event-memleak-fbf4abe230f3
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH ath-next] wifi: ath11k: fix leak in ath11k_service_ready_ext_event()
2026-07-27 23:39 [PATCH ath-next] wifi: ath11k: fix leak in ath11k_service_ready_ext_event() Jeff Johnson
@ 2026-07-29 9:05 ` Baochen Qiang
2026-07-30 9:35 ` Rameshkumar Sundaram
2026-07-31 14:41 ` Jeff Johnson
2 siblings, 0 replies; 4+ messages in thread
From: Baochen Qiang @ 2026-07-29 9:05 UTC (permalink / raw)
To: Jeff Johnson, Jeff Johnson; +Cc: ath11k, linux-wireless, linux-kernel
On 7/28/2026 7:39 AM, Jeff Johnson wrote:
> Currently, during ath11k_service_ready_ext_event() processing,
> svc_rdy_ext.mac_phy_caps can be allocated during TLV parsing. This is a
> temporary allocation that is freed on the success path, but not on the
> error path. If parsing succeeds far enough to allocate mac_phy_caps and
> then fails on a later TLV, the allocation leaks. So free the allocation
> on the error path.
>
> Compile tested only.
>
> Fixes: 5b90fc760db5 ("ath11k: fix wmi service ready ext tlv parsing")
> Assisted-by: Claude:claude-sonnet-4-6
> Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH ath-next] wifi: ath11k: fix leak in ath11k_service_ready_ext_event()
2026-07-27 23:39 [PATCH ath-next] wifi: ath11k: fix leak in ath11k_service_ready_ext_event() Jeff Johnson
2026-07-29 9:05 ` Baochen Qiang
@ 2026-07-30 9:35 ` Rameshkumar Sundaram
2026-07-31 14:41 ` Jeff Johnson
2 siblings, 0 replies; 4+ messages in thread
From: Rameshkumar Sundaram @ 2026-07-30 9:35 UTC (permalink / raw)
To: Jeff Johnson, Jeff Johnson; +Cc: ath11k, linux-wireless, linux-kernel
On 7/28/2026 5:09 AM, Jeff Johnson wrote:
> Currently, during ath11k_service_ready_ext_event() processing,
> svc_rdy_ext.mac_phy_caps can be allocated during TLV parsing. This is a
> temporary allocation that is freed on the success path, but not on the
> error path. If parsing succeeds far enough to allocate mac_phy_caps and
> then fails on a later TLV, the allocation leaks. So free the allocation
> on the error path.
>
> Compile tested only.
>
> Fixes: 5b90fc760db5 ("ath11k: fix wmi service ready ext tlv parsing")
> Assisted-by: Claude:claude-sonnet-4-6
> Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com>
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH ath-next] wifi: ath11k: fix leak in ath11k_service_ready_ext_event()
2026-07-27 23:39 [PATCH ath-next] wifi: ath11k: fix leak in ath11k_service_ready_ext_event() Jeff Johnson
2026-07-29 9:05 ` Baochen Qiang
2026-07-30 9:35 ` Rameshkumar Sundaram
@ 2026-07-31 14:41 ` Jeff Johnson
2 siblings, 0 replies; 4+ messages in thread
From: Jeff Johnson @ 2026-07-31 14:41 UTC (permalink / raw)
To: Jeff Johnson, Jeff Johnson; +Cc: ath11k, linux-wireless, linux-kernel
On Mon, 27 Jul 2026 16:39:41 -0700, Jeff Johnson wrote:
> Currently, during ath11k_service_ready_ext_event() processing,
> svc_rdy_ext.mac_phy_caps can be allocated during TLV parsing. This is a
> temporary allocation that is freed on the success path, but not on the
> error path. If parsing succeeds far enough to allocate mac_phy_caps and
> then fails on a later TLV, the allocation leaks. So free the allocation
> on the error path.
>
> [...]
Applied, thanks!
[1/1] wifi: ath11k: fix leak in ath11k_service_ready_ext_event()
commit: 0293be2212d319d59589082461abf2a9b626cd1c
Best regards,
--
Jeff Johnson <jeff.johnson@oss.qualcomm.com>
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-07-31 14:41 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-07-27 23:39 [PATCH ath-next] wifi: ath11k: fix leak in ath11k_service_ready_ext_event() Jeff Johnson
2026-07-29 9:05 ` Baochen Qiang
2026-07-30 9:35 ` Rameshkumar Sundaram
2026-07-31 14:41 ` Jeff Johnson
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®