From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-ej1-f54.google.com (mail-ej1-f54.google.com [209.85.218.54]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2DA55314D3D for ; Tue, 20 Jan 2026 20:25:19 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.218.54 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1768940721; cv=none; b=e4A6Rc/NYG1P8obHiHABwurn0DLPKHcHYF6XjfJE4LWA0gco5XCfH6AtiPEnP/uWyCHJhOmJaIC8gFDtZQzr4x6j/xoGXYLg1f0TctLpCDTfP8D8EsydjptNsrWUGLBvxNubbIA8OCFx1shpolRRyKAMDZPo+76a0Hrvg69YFiI= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1768940721; c=relaxed/simple; bh=T9nstNh5C/PMcxUcVmm/k+8q89ivN6duC8EN8FC+Dhk=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=KIuFwnhdxWgDK0PJDlFIl5fqkBPhckX5mfj6X6P1vOO+Ex8R3uOxKjxRw2GDBgTV4gpkFUxZUxTMjvvaBOVkBXeab6jW1p2tdurEIgBWS9ECpAKvgljeblK70awjdhJDeOJ+bBqQ9bFL0D04mFeFmPPEpn/Bw588HsS+XvLyenI= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=ETNDAPF7; arc=none smtp.client-ip=209.85.218.54 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="ETNDAPF7" Received: by mail-ej1-f54.google.com with SMTP id a640c23a62f3a-b86f3e88d4dso1032797066b.0 for ; Tue, 20 Jan 2026 12:25:18 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1768940717; x=1769545517; darn=vger.kernel.org; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :from:to:cc:subject:date:message-id:reply-to; bh=BbvptpwtewhcN+InYiYZTWkrRmvBxAsjQT9HVhHSR5E=; b=ETNDAPF7h153ndeXoro1C0ZvcKSuXi6PHDX42uRhsgcIE2aLx1XJ2Eh5+QV9vsu3Rs Z6hXAardaV/lTUYmDlAm4/+yWulZ3wsnSsFGDvA7+QE5+x3vBASL16GsLOGa56orkmN5 gl4w7C6/uqz1kFR91B+4hSe5/+ezdLsspHXlX/TtLGDzu0tJQUXuca0M9A7jm08eSoFz t4bqKggyowSkkY+M/gqSDcUhO4bac7N1dZa0vvED+QcjnHUUvUd+PnddDPd0llN1u+4J zggD5lWXteZMfiTEMcLDs0f0xwzcB142cNu4+rLrJ13ixWGCPpzmBAKFjZBormxkrsfs qQnA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1768940717; x=1769545517; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=BbvptpwtewhcN+InYiYZTWkrRmvBxAsjQT9HVhHSR5E=; b=Q6T7lecHDpdJXkkb0EWJkeszAeWI8vBxgMQbJZZZH7ql324JykI1bef3cJaFaSVhxc k7TezLTqTX4S+0EVzun7xE4wbbH2dFWyisaYtW+P0Zm1WYz7UBSFnP5VmuSCPFwm32wD c8Ow6TcSA3RPE66LOyutLjuJHML5qobZBaNsrKa5G+tb0+egauhe8lyzP6cKsOndgp6O N46GOQ0RDDXgyresf8mAFCarOehx7z1LhQfWakWDYUpkVsTwlnzRmVCpsVKWHVTaSf3d iB5U9BivXWPXIhMl+xIB7BrJNVuCIfZ3GMEkfXGJn1q/+OuHFB19o+IV1PNHKuoue/uE eBBA== X-Forwarded-Encrypted: i=1; AJvYcCWf3IEz64TsyJ2xBo59swj5y/St4vMMqiVq5sJXMcZRnL9yW7adyB+GLSu0jU/JJiLi4Xa7YN1N5RJIC8I=@vger.kernel.org X-Gm-Message-State: AOJu0YyPvJY/0/v70jyrWfPbpAeNKAWnj3wLHTjNZ4vEpIC9BZJCHCSr KPChUaAZrUnlrRVyorJMaOcE+XOlNAJY0VvPI01lpzA27MPPihVqOrE0 X-Gm-Gg: AY/fxX692CzSprxa3AXj/gWvM1iw6nPRZ30cU/6VPa2u0fpsqdfi+NY7updQ42SgInx mXrD25ybbRuiLMXshuBlnFxqHjyNbrq+r55/8E6L39DictZFAf4stjOcHVZ/ewTHYk5erqIexT5 qOpAs2P5VSWbhsFslibBcbaakKeau+A46EOtFlgCqFK/dZJfs8Ru4t0BQB5Diha3yRRhMpzR045 v8e1ijuZdHW2xlpI6q4EvwmIt2EkwuR8F4G2u5BX7EJQhgtLi+n5e7zYH5T3z9UA68oiFeHuMb5 /LLMrrYot7efb/8CIpO4KuOTUIjzr29gTTzjdeNIzMILJcho/FdbYoz/7lzVcShB+75Y6qCQU/p 64bXPE/t14HuSjbSGaL80fkZRIhWALh32tsQ05zltvgxMyRTTQeMbpVJwYBerKZveWKlK/CuhbC bVG7NJt7ZN8KT2ZlwvMqpr5a8I2fByr8Rm/maXMcuUzAs/17rZD5Px5ksUNGaFIa8/W7ug1YOWf Unyoaxjcw== X-Received: by 2002:a17:907:3e04:b0:b83:a6b6:ed74 with SMTP id a640c23a62f3a-b8792d59928mr1205701166b.19.1768940717146; Tue, 20 Jan 2026 12:25:17 -0800 (PST) Received: from shift (p200300d5ff09750050f496fffe46beef.dip0.t-ipconnect.de. [2003:d5:ff09:7500:50f4:96ff:fe46:beef]) by smtp.gmail.com with ESMTPSA id a640c23a62f3a-b87959fbd23sm1477805966b.51.2026.01.20.12.25.16 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 20 Jan 2026 12:25:16 -0800 (PST) Received: from localhost ([127.0.0.1]) by shift with esmtp (Exim 4.99.1) (envelope-from ) id 1viIHr-00000000j5e-44cl; Tue, 20 Jan 2026 21:25:15 +0100 Message-ID: <71ec168e-423b-4269-88b9-56e08c1d8110@gmail.com> Date: Tue, 20 Jan 2026 21:25:15 +0100 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH v2] wifi: p54: Fix memory leak in p54_beacon_update() To: Zilin Guan Cc: quic_rdevanat@quicinc.com, johannes.berg@intel.com, linux-wireless@vger.kernel.org, linux-kernel@vger.kernel.org, johannes@sipsolutions.net, jianhao.xu@seu.edu.cn References: <20260120130144.2662132-1-zilin@seu.edu.cn> Content-Language: de-DE From: Christian Lamparter In-Reply-To: <20260120130144.2662132-1-zilin@seu.edu.cn> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit Hi, I'm sorry for not seeing this sooner. Yes, 24hrs are passed. On 1/20/26 2:01 PM, Zilin Guan wrote: > In p54_beacon_update(), beacon is allocated via ieee80211_beacon_get(). > If p54_beacon_format_ie_tim() fails, the function returns immediately > without freeing the allocated beacon skb, leading to a memory leak. > > Since no other references to this memory exist, it must be freed locally > before returning the error. Fix this by freeing the buffer using > dev_kfree_skb_any() in the error path. > > Compile tested only. Issue found using a prototype static analysis tool > and code review. Ok, from what I remember, this return basically is/was and likely will be a dead-code path. So adding something there is only there to "look" good for the static analysis tools. But many commits like these have been merged before. As long as it is mentioned that static analysis was the reason for this. Yeah sure why not. Reason being why this is dead-code is that in order for the path to trigger, mac80211's ieee80211_beacon_get must have prepared an invalid beacon (with an invalid TIM Element) to start with... And looking at ieee80211_beacon_add_tim_pvb, it still looks to me like the IE length can't be less than 3 ever. But, I've been wrong before, if you do see please correct me. (If not, you don't neet to really bother with the Fixes-Tag) Cheers, Christian > > Fixes: e5ea92a7528d ("p54: AP & Ad-hoc testing") > Signed-off-by: Zilin Guan > --- > Changes in v2: > - Correct the Fixes tag to point to the commit that introduced this issue. > > drivers/net/wireless/intersil/p54/main.c | 4 +++- > 1 file changed, 3 insertions(+), 1 deletion(-) > > diff --git a/drivers/net/wireless/intersil/p54/main.c b/drivers/net/wireless/intersil/p54/main.c > index 2ec3655f1a9c..57a62108cbc3 100644 > --- a/drivers/net/wireless/intersil/p54/main.c > +++ b/drivers/net/wireless/intersil/p54/main.c > @@ -143,8 +143,10 @@ static int p54_beacon_update(struct p54_common *priv, > if (!beacon) > return -ENOMEM; > ret = p54_beacon_format_ie_tim(beacon); > - if (ret) > + if (ret) { > + dev_kfree_skb_any(beacon); > return ret; > + } Hmm > > /* > * During operation, the firmware takes care of beaconing.