From nobody Fri Dec 19 20:14:08 2025 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0CD272892DF; Sun, 24 Mar 2024 23:47:23 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1711324045; cv=none; b=fN/Fli4E286v3tfd7OgKsmNnLVUX90UzyrW8naTkn/G9d9lwQBaJ3n4OZQWmzCkM52Upxic+mePXBQlTFaEcX/aofIOf6eDuOghWaJHbD2mLY9vNC8WwpBQFEPqWh/1JlOyZftbJCb+mLMFtSlptsvjaNWBUW+k0GLSQgjy2B+4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1711324045; c=relaxed/simple; bh=eTI9IOKkvtOB8T26gH1qSqbthfn8ohH424sihv1I7Fk=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=lrhKFPfnSQ4oMLN7s/28Gq49mzLAIGCfNcJX/FBuGbSCRA6gSvbRuUZMorRKyzW/qkO5uCPO32W77ZKUtmsIxAxv3oV/5bSR+g+rjp/isXhKysYKqJyl27e0Z2qEKmoQ0CcT2lv427WX4TfXCi9zIprI1nljUCdjjOVtZvtGhkk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=RtxIqAr2; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="RtxIqAr2" Received: by smtp.kernel.org (Postfix) with ESMTPSA id E77C2C433F1; Sun, 24 Mar 2024 23:47:22 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1711324043; bh=eTI9IOKkvtOB8T26gH1qSqbthfn8ohH424sihv1I7Fk=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=RtxIqAr29iPGypJhjvbrgTTLsgVfRK7ks53JQCAI0FzRRDx9ustsImkckwIihwjDt fx6RY5MKJfu8pXKpSGRqVG4Gy+8BJKNHla2bZ1k/oYCPAxPAxIRd1wDAsZwRe2FPp4 QYFi6aFniqqA4LVzq3RBYeUOwycREV3U5yqYEtQTtxNHLBK4l4iELyU1Mw4Bd7sgC/ UbZ1RbYfrB4Md6AiEngy0R0LTGisy3xK51ZuuNgCVSY3C9uue4FK7RlyiXDXPeLz9+ 1R+tWo4NQ3oZKb3iU42y4LXN6tjszSDL4i8grYQxjZLndDMuomOPK6f1Ddd26pmLHG RTHfceNWIjF0Q== From: Sasha Levin To: linux-kernel@vger.kernel.org, stable@vger.kernel.org Cc: Zhipeng Lu , Kalle Valo , Sasha Levin Subject: [PATCH 5.4 044/183] wifi: libertas: fix some memleaks in lbs_allocate_cmd_buffer() Date: Sun, 24 Mar 2024 19:44:17 -0400 Message-ID: <20240324234638.1355609-45-sashal@kernel.org> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20240324234638.1355609-1-sashal@kernel.org> References: <20240324234638.1355609-1-sashal@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-stable: review X-Patchwork-Hint: Ignore Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Zhipeng Lu [ Upstream commit 5f0e4aede01cb01fa633171f0533affd25328c3a ] In the for statement of lbs_allocate_cmd_buffer(), if the allocation of cmdarray[i].cmdbuf fails, both cmdarray and cmdarray[i].cmdbuf needs to be freed. Otherwise, there will be memleaks in lbs_allocate_cmd_buffer(). Fixes: 876c9d3aeb98 ("[PATCH] Marvell Libertas 8388 802.11b/g USB driver") Signed-off-by: Zhipeng Lu Signed-off-by: Kalle Valo Link: https://msgid.link/20240126075336.2825608-1-alexious@zju.edu.cn Signed-off-by: Sasha Levin --- drivers/net/wireless/marvell/libertas/cmd.c | 13 +++++++++++-- 1 file changed, 11 insertions(+), 2 deletions(-) diff --git a/drivers/net/wireless/marvell/libertas/cmd.c b/drivers/net/wire= less/marvell/libertas/cmd.c index a4d9dd73b2588..db9a852fa58a3 100644 --- a/drivers/net/wireless/marvell/libertas/cmd.c +++ b/drivers/net/wireless/marvell/libertas/cmd.c @@ -1133,7 +1133,7 @@ int lbs_allocate_cmd_buffer(struct lbs_private *priv) if (!cmdarray[i].cmdbuf) { lbs_deb_host("ALLOC_CMD_BUF: ptempvirtualaddr is NULL\n"); ret =3D -1; - goto done; + goto free_cmd_array; } } =20 @@ -1141,8 +1141,17 @@ int lbs_allocate_cmd_buffer(struct lbs_private *priv) init_waitqueue_head(&cmdarray[i].cmdwait_q); lbs_cleanup_and_insert_cmd(priv, &cmdarray[i]); } - ret =3D 0; + return 0; =20 +free_cmd_array: + for (i =3D 0; i < LBS_NUM_CMD_BUFFERS; i++) { + if (cmdarray[i].cmdbuf) { + kfree(cmdarray[i].cmdbuf); + cmdarray[i].cmdbuf =3D NULL; + } + } + kfree(priv->cmd_array); + priv->cmd_array =3D NULL; done: return ret; } --=20 2.43.0