From nobody Wed Oct 15 22:39:51 2025 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5A8CC2762B2; Sun, 24 Mar 2024 23:36:25 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1711323386; cv=none; b=Ws5OYnI7faqnMydUAiSMFv03vkHcyo4f0q3gmQnzduzJDR4U2jNe2lPNHvL5epy1XtswZSZfxZ2KyoRk6XPQ5eI5rOL8rcRsvnvhK7CZSgooiDGsgkMqgl5sJm6Wn7M/bt9v0U3W+npUmk9uSYG1KyF4r1gzB6mlCYfs1gehQfI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1711323386; c=relaxed/simple; bh=eTI9IOKkvtOB8T26gH1qSqbthfn8ohH424sihv1I7Fk=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=QZaWU36lUmxwtCnjELLAzzEbG8ebZye9U88jUj+lvgnLX33SZt3W8msuKhGz2kGCEbVIEo28ibMK5bNbRn7sLXiCJay6ep1/GBpAPcmxHOv9jg9lenydhnytBHqv8ULCp0wnrkEh+MeAcLcszzrNJFWuwnKgGFNaXalgqWGDzNg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=tEsbj28x; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="tEsbj28x" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 9ABC5C43399; Sun, 24 Mar 2024 23:36:24 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1711323385; bh=eTI9IOKkvtOB8T26gH1qSqbthfn8ohH424sihv1I7Fk=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=tEsbj28xp7FODlhEqitMa5fswOPRrLiZ01WPNxZVMbtdqxldSuOWyeSD6fdTGTF0D DT7D5yH9paIkhmisT/rWdeaud7s7pGATCTGNMeO3qj3rLEmwp7wd+dC0cMCIHGzGqM ZuSJCGIcOp6aUDGuATIjcJM7teaZC2enzF7ygzI2fxfiWpLAAkTBKeLmFiqbFXNPP1 W4/8lslv4W++YixO08NsxL0ZZZxUPEhtysVZTj/hfUmJ4qcXAtFgXVQPD/9fsNMFN1 NSIz+mKXR8MAGE4tgJrMd6USd04JOIBL1tPQ+iN53K0ZTXxfc1SuQqldADow0Eh2ZQ rYJcRISiKKB9w== From: Sasha Levin To: linux-kernel@vger.kernel.org, stable@vger.kernel.org Cc: Zhipeng Lu , Kalle Valo , Sasha Levin Subject: [PATCH 5.15 085/317] wifi: libertas: fix some memleaks in lbs_allocate_cmd_buffer() Date: Sun, 24 Mar 2024 19:31:05 -0400 Message-ID: <20240324233458.1352854-86-sashal@kernel.org> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20240324233458.1352854-1-sashal@kernel.org> References: <20240324233458.1352854-1-sashal@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-stable: review X-Patchwork-Hint: Ignore Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Zhipeng Lu [ Upstream commit 5f0e4aede01cb01fa633171f0533affd25328c3a ] In the for statement of lbs_allocate_cmd_buffer(), if the allocation of cmdarray[i].cmdbuf fails, both cmdarray and cmdarray[i].cmdbuf needs to be freed. Otherwise, there will be memleaks in lbs_allocate_cmd_buffer(). Fixes: 876c9d3aeb98 ("[PATCH] Marvell Libertas 8388 802.11b/g USB driver") Signed-off-by: Zhipeng Lu Signed-off-by: Kalle Valo Link: https://msgid.link/20240126075336.2825608-1-alexious@zju.edu.cn Signed-off-by: Sasha Levin --- drivers/net/wireless/marvell/libertas/cmd.c | 13 +++++++++++-- 1 file changed, 11 insertions(+), 2 deletions(-) diff --git a/drivers/net/wireless/marvell/libertas/cmd.c b/drivers/net/wire= less/marvell/libertas/cmd.c index a4d9dd73b2588..db9a852fa58a3 100644 --- a/drivers/net/wireless/marvell/libertas/cmd.c +++ b/drivers/net/wireless/marvell/libertas/cmd.c @@ -1133,7 +1133,7 @@ int lbs_allocate_cmd_buffer(struct lbs_private *priv) if (!cmdarray[i].cmdbuf) { lbs_deb_host("ALLOC_CMD_BUF: ptempvirtualaddr is NULL\n"); ret =3D -1; - goto done; + goto free_cmd_array; } } =20 @@ -1141,8 +1141,17 @@ int lbs_allocate_cmd_buffer(struct lbs_private *priv) init_waitqueue_head(&cmdarray[i].cmdwait_q); lbs_cleanup_and_insert_cmd(priv, &cmdarray[i]); } - ret =3D 0; + return 0; =20 +free_cmd_array: + for (i =3D 0; i < LBS_NUM_CMD_BUFFERS; i++) { + if (cmdarray[i].cmdbuf) { + kfree(cmdarray[i].cmdbuf); + cmdarray[i].cmdbuf =3D NULL; + } + } + kfree(priv->cmd_array); + priv->cmd_array =3D NULL; done: return ret; } --=20 2.43.0