drivers/net/wireless/ath/ath12k/mac.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-)
On failure, ath12k_mac_setup_channels_rates() frees band channel
arrays but leaves the pointers set, or clears the wrong band after a
copy-paste typo (6 GHz free paired with a 2 GHz NULL). Clear the
matching sbands[].channels pointer after each kfree().
Compile tested only.
Signed-off-by: Linkai Gong <gonglinkai@kylinos.cn>
---
v2:
- reword commit message (dangling pointers + typo, not double-free)
- drop Fixes tag
- note compile tested only
v1: https://lore.kernel.org/all/20260731093816.1771338-1-gonglinkai@kylinos.cn/
drivers/net/wireless/ath/ath12k/mac.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/net/wireless/ath/ath12k/mac.c b/drivers/net/wireless/ath/ath12k/mac.c
index a0928890671a..5468a8d2d5d5 100644
--- a/drivers/net/wireless/ath/ath12k/mac.c
+++ b/drivers/net/wireless/ath/ath12k/mac.c
@@ -14275,6 +14275,7 @@ static int ath12k_mac_setup_channels_rates(struct ath12k *ar,
sizeof(ath12k_6ghz_channels), GFP_KERNEL);
if (!channels) {
kfree(ar->mac.sbands[NL80211_BAND_2GHZ].channels);
+ ar->mac.sbands[NL80211_BAND_2GHZ].channels = NULL;
return -ENOMEM;
}
@@ -14325,7 +14326,9 @@ static int ath12k_mac_setup_channels_rates(struct ath12k *ar,
GFP_KERNEL);
if (!channels) {
kfree(ar->mac.sbands[NL80211_BAND_2GHZ].channels);
+ ar->mac.sbands[NL80211_BAND_2GHZ].channels = NULL;
kfree(ar->mac.sbands[NL80211_BAND_6GHZ].channels);
+ ar->mac.sbands[NL80211_BAND_6GHZ].channels = NULL;
return -ENOMEM;
}
@@ -14365,7 +14368,7 @@ static int ath12k_mac_setup_channels_rates(struct ath12k *ar,
kfree(ar->mac.sbands[NL80211_BAND_2GHZ].channels);
ar->mac.sbands[NL80211_BAND_2GHZ].channels = NULL;
kfree(ar->mac.sbands[NL80211_BAND_6GHZ].channels);
- ar->mac.sbands[NL80211_BAND_2GHZ].channels = NULL;
+ ar->mac.sbands[NL80211_BAND_6GHZ].channels = NULL;
kfree(channels);
band->channels = NULL;
return ret;
--
2.25.1
On Tue, 11 Aug 2026 10:05:23 +0800, Linkai Gong wrote:
> On failure, ath12k_mac_setup_channels_rates() frees band channel
> arrays but leaves the pointers set, or clears the wrong band after a
> copy-paste typo (6 GHz free paired with a 2 GHz NULL). Clear the
> matching sbands[].channels pointer after each kfree().
>
> Compile tested only.
>
> [...]
Applied, thanks!
[1/1] wifi: ath12k: clear dangling channel pointers on error paths
commit: 507478f6f93864978a399173d4f54c8a987c8235
Best regards,
--
Jeff Johnson <jeff.johnson@oss.qualcomm.com>
On 8/11/2026 7:35 AM, Linkai Gong wrote:
> On failure, ath12k_mac_setup_channels_rates() frees band channel
> arrays but leaves the pointers set, or clears the wrong band after a
> copy-paste typo (6 GHz free paired with a 2 GHz NULL). Clear the
> matching sbands[].channels pointer after each kfree().
>
> Compile tested only.
>
> Signed-off-by: Linkai Gong <gonglinkai@kylinos.cn>
> ---
> v2:
> - reword commit message (dangling pointers + typo, not double-free)
> - drop Fixes tag
> - note compile tested only
>
> v1: https://lore.kernel.org/all/20260731093816.1771338-1-gonglinkai@kylinos.cn/
>
> drivers/net/wireless/ath/ath12k/mac.c | 5 ++++-
> 1 file changed, 4 insertions(+), 1 deletion(-)
>
> diff --git a/drivers/net/wireless/ath/ath12k/mac.c b/drivers/net/wireless/ath/ath12k/mac.c
> index a0928890671a..5468a8d2d5d5 100644
> --- a/drivers/net/wireless/ath/ath12k/mac.c
> +++ b/drivers/net/wireless/ath/ath12k/mac.c
> @@ -14275,6 +14275,7 @@ static int ath12k_mac_setup_channels_rates(struct ath12k *ar,
> sizeof(ath12k_6ghz_channels), GFP_KERNEL);
> if (!channels) {
> kfree(ar->mac.sbands[NL80211_BAND_2GHZ].channels);
> + ar->mac.sbands[NL80211_BAND_2GHZ].channels = NULL;
> return -ENOMEM;
> }
>
> @@ -14325,7 +14326,9 @@ static int ath12k_mac_setup_channels_rates(struct ath12k *ar,
> GFP_KERNEL);
> if (!channels) {
> kfree(ar->mac.sbands[NL80211_BAND_2GHZ].channels);
> + ar->mac.sbands[NL80211_BAND_2GHZ].channels = NULL;
> kfree(ar->mac.sbands[NL80211_BAND_6GHZ].channels);
> + ar->mac.sbands[NL80211_BAND_6GHZ].channels = NULL;
> return -ENOMEM;
> }
>
> @@ -14365,7 +14368,7 @@ static int ath12k_mac_setup_channels_rates(struct ath12k *ar,
> kfree(ar->mac.sbands[NL80211_BAND_2GHZ].channels);
> ar->mac.sbands[NL80211_BAND_2GHZ].channels = NULL;
> kfree(ar->mac.sbands[NL80211_BAND_6GHZ].channels);
> - ar->mac.sbands[NL80211_BAND_2GHZ].channels = NULL;
> + ar->mac.sbands[NL80211_BAND_6GHZ].channels = NULL;
> kfree(channels);
> band->channels = NULL;
> return ret;
Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com>
On 8/11/2026 10:05 AM, Linkai Gong wrote: > On failure, ath12k_mac_setup_channels_rates() frees band channel > arrays but leaves the pointers set, or clears the wrong band after a > copy-paste typo (6 GHz free paired with a 2 GHz NULL). Clear the > matching sbands[].channels pointer after each kfree(). > > Compile tested only. > > Signed-off-by: Linkai Gong <gonglinkai@kylinos.cn> Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
© 2016 - 2026 Red Hat, Inc.