From nobody Tue Sep 29 02:38:12 2026 Received: from mailgw.kylinos.cn (mailgw.kylinos.cn [124.126.103.232]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E9030414A15; Thu, 13 Aug 2026 08:23:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=124.126.103.232 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786609411; cv=none; b=UjvFQ8aSU6+alfEsSZAZQCN+tnzvy2/9cbCa2cOu5oARybc5oMq3YWP3rMTRCyZz+//4AhuMW3MBv45ZEF+pY6d8+7J1Y98ajdWzkCrxEyiOm1HvkYSPBlksrDNnTpX41Xf5agmHsu326zckzRHsLf9lohEZErrNxhDpJ/k06bY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786609411; c=relaxed/simple; bh=hF1a0Y6lOJm7iA2dFbur1YquVnlb2C++Wv0JRPEAgOk=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=FHYh1kAAYYj6y20nwr1qPIn2Ja1W+X58LUP/TnoRj1Iejo11PdWvwwzb9WafxGb1lLa1F+H08WnU6NU588q8TAlXLgIicWnxTdv6SV0n1MPnXqju+nwWfsbROnZNxmf0QC65y8uIuyLFKcEl42KGcbVwTIjx5vHQxzpkOzj2Rfs= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn; spf=pass smtp.mailfrom=kylinos.cn; arc=none smtp.client-ip=124.126.103.232 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=kylinos.cn X-UUID: 3ed2213a96f011f1aa26b74ffac11d73-20260813 X-CID-P-RULE: Release_Ham X-CID-O-INFO: VERSION:1.3.12,REQID:85e73a2b-710b-4f1b-a761-de25a621d486,IP:0,U RL:0,TC:0,Content:0,EDM:25,RT:0,SF:0,FILE:0,BULK:0,RULE:Release_Ham,ACTION :release,TS:25 X-CID-META: VersionHash:e7bac3a,CLOUDID:283f105edddc1f09ef27d1275b0461a9,BulkI D:nil,BulkQuantity:0,Recheck:0,SF:81|82|102|850|865|898,TC:nil,Content:0|1 5|50,EDM:5,IP:nil,URL:0,File:nil,RT:nil,Bulk:nil,QS:nil,BEC:nil,COL:0,OSI: 0,OSA:0,AV:0,LES:1,SPR:NO,DKR:0,DKP:0,BRR:0,BRE:0,ARC:0 X-CID-BVR: 2,SSN|SDN X-CID-BAS: 2,SSN|SDN,0,_ X-CID-FACTOR: TF_CID_SPAM_SNR X-CID-RHF: D41D8CD98F00B204E9800998ECF8427E X-UUID: 3ed2213a96f011f1aa26b74ffac11d73-20260813 X-User: lilinmao@kylinos.cn Received: from localhost.localdomain [(10.44.16.150)] by mailgw.kylinos.cn (envelope-from ) (Generic MTA with TLSv1.3 TLS_AES_256_GCM_SHA384 256/256) with ESMTP id 716133087; Thu, 13 Aug 2026 16:23:21 +0800 From: Linmao Li To: Jeff Chen Cc: Francesco Dolcini , Johannes Berg , linux-wireless@vger.kernel.org, linux-kernel@vger.kernel.org, Linmao Li Subject: [PATCH wireless-next 1/3] wifi: nxpwifi: wait for the wakeup timer before the adapter is freed Date: Thu, 13 Aug 2026 16:23:13 +0800 Message-Id: <20260813082315.1390321-2-lilinmao@kylinos.cn> X-Mailer: git-send-email 2.25.1 In-Reply-To: <20260813082315.1390321-1-lilinmao@kylinos.cn> References: <20260813082315.1390321-1-lilinmao@kylinos.cn> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" nxpwifi_adapter_cleanup() stops adapter->wakeup_timer with timer_delete(), which does not wait for a running callback. The callback goes on using the adapter: wakeup_timer_fn() sets adapter->hw_status, walks the command queues through nxpwifi_cancel_all_pending_cmd() and calls adapter->if_ops.card_reset(). Both paths that reach nxpwifi_adapter_cleanup() free the adapter right afterwards, through nxpwifi_free_adapter() in nxpwifi_remove_card() and in the nxpwifi_add_card() error unwind. Use timer_delete_sync() so the callback has finished before the adapter is released. mwifiex fixed the same issue in commit ae5e95d41574 ("wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup()"). Fixes: 73b01e57ed3e ("wifi: nxp: add nxpwifi driver for IW61x") Signed-off-by: Linmao Li Reviewed-by: Jeff Chen --- drivers/net/wireless/nxp/nxpwifi/init.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/net/wireless/nxp/nxpwifi/init.c b/drivers/net/wireless= /nxp/nxpwifi/init.c index b128fc9fe31a2..69b27fce5ce65 100644 --- a/drivers/net/wireless/nxp/nxpwifi/init.c +++ b/drivers/net/wireless/nxp/nxpwifi/init.c @@ -328,7 +328,7 @@ static void nxpwifi_invalidate_lists(struct nxpwifi_ada= pter *adapter) static void nxpwifi_adapter_cleanup(struct nxpwifi_adapter *adapter) { - timer_delete(&adapter->wakeup_timer); + timer_delete_sync(&adapter->wakeup_timer); nxpwifi_cancel_all_pending_cmd(adapter); wake_up_interruptible(&adapter->cmd_wait_q.wait); wake_up_interruptible(&adapter->hs_activate_wait_q); --=20 2.25.1 From nobody Tue Sep 29 02:38:12 2026 Received: from mailgw.kylinos.cn (mailgw.kylinos.cn [124.126.103.232]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6115C36B93C; Thu, 13 Aug 2026 08:23:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=124.126.103.232 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786609411; cv=none; b=VCFA2+siBv7yHlgyYP8SHyjfhULQLtaU9mdHjqxzMDPv8orPv3FsOmO6Eg65xKQjUaoX2MZWINBa9ACWuR1ky80iHngbB/T+6x3hJXZMMXjiI4t1taLdLW/8Z9ISy1sDQ2AJinU8zUJsFu6QOxvNMV1FnnAQQkx9q9+7//npHDQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786609411; c=relaxed/simple; bh=V8iufdE/Qu2vO8v9vJPMDhg0T6pd6TTK+ELI3S4anDY=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=XZhH1QEOlBn3+CBbcQLCcbxgv/PgK6aMI1LPdWMA9uMe45UrY2sOEIsCXf3e/QY75h3l5cNc3n1IsmCjWRo/Y7ZVDNZHmQRRH3+yVGth2qMT84AAHNhacdqLq6+unVRZIxPWnlVPbLx729TcJ9jsFMrcS/uJwRkwBsskFxuq0eo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn; spf=pass smtp.mailfrom=kylinos.cn; arc=none smtp.client-ip=124.126.103.232 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=kylinos.cn X-UUID: 3fae703696f011f1aa26b74ffac11d73-20260813 X-CID-P-RULE: Release_Ham X-CID-O-INFO: VERSION:1.3.12,REQID:f8c38671-2144-42b6-9f85-a8895b2623a1,IP:0,U RL:0,TC:0,Content:0,EDM:0,RT:0,SF:0,FILE:0,BULK:0,RULE:Release_Ham,ACTION: release,TS:0 X-CID-META: VersionHash:e7bac3a,CLOUDID:4d4ef381cc9e27c2f46cba813b709050,BulkI D:nil,BulkQuantity:0,Recheck:0,SF:81|82|102|850|865|898,TC:nil,Content:0|1 5|50,EDM:-3,IP:nil,URL:0,File:nil,RT:nil,Bulk:nil,QS:nil,BEC:nil,COL:0,OSI :0,OSA:0,AV:0,LES:1,SPR:NO,DKR:0,DKP:0,BRR:0,BRE:0,ARC:0 X-CID-BVR: 2,SSN|SDN X-CID-BAS: 2,SSN|SDN,0,_ X-CID-FACTOR: TF_CID_SPAM_SNR X-CID-RHF: D41D8CD98F00B204E9800998ECF8427E X-UUID: 3fae703696f011f1aa26b74ffac11d73-20260813 X-User: lilinmao@kylinos.cn Received: from localhost.localdomain [(10.44.16.150)] by mailgw.kylinos.cn (envelope-from ) (Generic MTA with TLSv1.3 TLS_AES_256_GCM_SHA384 256/256) with ESMTP id 1004004295; Thu, 13 Aug 2026 16:23:22 +0800 From: Linmao Li To: Jeff Chen Cc: Francesco Dolcini , Johannes Berg , linux-wireless@vger.kernel.org, linux-kernel@vger.kernel.org, Linmao Li Subject: [PATCH wireless-next 2/3] wifi: nxpwifi: free the aggregation buffer when the RA list disappears Date: Thu, 13 Aug 2026 16:23:14 +0800 Message-Id: <20260813082315.1390321-3-lilinmao@kylinos.cn> X-Mailer: git-send-email 2.25.1 In-Reply-To: <20260813082315.1390321-1-lilinmao@kylinos.cn> References: <20260813082315.1390321-1-lilinmao@kylinos.cn> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" nxpwifi_11n_aggregate_pkt() drops ra_list_spinlock while it copies each subframe, so it rechecks the RA list after taking the lock again. The check inside the aggregation loop returns without releasing the skb_aggr it has been filling, leaking one tx_buf_size buffer along with the subframes already aggregated into it. Release skb_aggr there, the way the same check on the -EBUSY path already does. mwifiex fixed the same issue in commit 990a73dec3fd ("wifi: mwifiex: Fix memory leak in mwifiex_11n_aggregate_pkt()"). Fixes: 73b01e57ed3e ("wifi: nxp: add nxpwifi driver for IW61x") Signed-off-by: Linmao Li Reviewed-by: Jeff Chen --- drivers/net/wireless/nxp/nxpwifi/11n_aggr.c | 1 + 1 file changed, 1 insertion(+) diff --git a/drivers/net/wireless/nxp/nxpwifi/11n_aggr.c b/drivers/net/wire= less/nxp/nxpwifi/11n_aggr.c index be7080f2a6ce7..54933c42c960d 100644 --- a/drivers/net/wireless/nxp/nxpwifi/11n_aggr.c +++ b/drivers/net/wireless/nxp/nxpwifi/11n_aggr.c @@ -168,6 +168,7 @@ nxpwifi_11n_aggregate_pkt(struct nxpwifi_private *priv, =20 if (!nxpwifi_is_ralist_valid(priv, pra_list, ptrindex)) { spin_unlock_bh(&priv->wmm.ra_list_spinlock); + nxpwifi_write_data_complete(adapter, skb_aggr, 1, -1); return -ENOENT; } =20 --=20 2.25.1 From nobody Tue Sep 29 02:38:12 2026 Received: from mailgw.kylinos.cn (mailgw.kylinos.cn [124.126.103.232]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1A55636728F; Thu, 13 Aug 2026 08:23:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=124.126.103.232 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786609420; cv=none; b=YRs8F3R6f1bX5Z9XyQj5ltLH8qn3M1szMApVqB3n56WyVDU9z19mvfK3veJ4RKuF16pKHAZFiTI6m4RfCifBXFTd35oSGnhNANhvfVaEF73+sFBGF9hRJhzO74RNoWALbE1ssTyzOmSc3Onnm2rsHRTm3iKZwTMJ3zlbdJ9avR0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786609420; c=relaxed/simple; bh=l45JuBwYMJMWQGawB7yPHvVIE+PKPgwuPIEfnr4K+3o=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=poXSdW7oXLITCpyvIt3wNWaesvzBJuM3YyGYiwYXBiWNGGBl03GYSlkyaKhgmwxNuZMTtWfaBbWlLvE4h1HDIemBQ+uMBKobfe9Sd8tDBnAJo0pAN3khLiCZDO69qmdLXxbLkd5/8jtGv3fO9Ha0FE+Ptn+TuL4w2uUd8vM6KMM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn; spf=pass smtp.mailfrom=kylinos.cn; arc=none smtp.client-ip=124.126.103.232 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=kylinos.cn X-UUID: 40c6d26096f011f1aa26b74ffac11d73-20260813 X-CID-P-RULE: Release_Ham X-CID-O-INFO: VERSION:1.3.12,REQID:2e8c6304-221b-46b0-8ed3-269593f7c17f,IP:0,U RL:0,TC:0,Content:-25,EDM:25,RT:0,SF:0,FILE:0,BULK:0,RULE:Release_Ham,ACTI ON:release,TS:0 X-CID-META: VersionHash:e7bac3a,CLOUDID:7a499a031a488128c09bdb12be4f973f,BulkI D:nil,BulkQuantity:0,Recheck:0,SF:81|82|102|850|865|898,TC:nil,Content:0|1 5|50,EDM:5,IP:nil,URL:0,File:nil,RT:nil,Bulk:nil,QS:nil,BEC:nil,COL:0,OSI: 0,OSA:0,AV:0,LES:1,SPR:NO,DKR:0,DKP:0,BRR:0,BRE:0,ARC:0 X-CID-BVR: 2,SSN|SDN X-CID-BAS: 2,SSN|SDN,0,_ X-CID-FACTOR: TF_CID_SPAM_SNR X-CID-RHF: D41D8CD98F00B204E9800998ECF8427E X-UUID: 40c6d26096f011f1aa26b74ffac11d73-20260813 X-User: lilinmao@kylinos.cn Received: from localhost.localdomain [(10.44.16.150)] by mailgw.kylinos.cn (envelope-from ) (Generic MTA with TLSv1.3 TLS_AES_256_GCM_SHA384 256/256) with ESMTP id 59013449; Thu, 13 Aug 2026 16:23:24 +0800 From: Linmao Li To: Jeff Chen Cc: Francesco Dolcini , Johannes Berg , linux-wireless@vger.kernel.org, linux-kernel@vger.kernel.org, Linmao Li Subject: [PATCH wireless-next 3/3] wifi: nxpwifi: zero the channel statistics array Date: Thu, 13 Aug 2026 16:23:15 +0800 Message-Id: <20260813082315.1390321-4-lilinmao@kylinos.cn> X-Mailer: git-send-email 2.25.1 In-Reply-To: <20260813082315.1390321-1-lilinmao@kylinos.cn> References: <20260813082315.1390321-1-lilinmao@kylinos.cn> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" adapter->chan_stats comes from vmalloc(), which does not clear the memory, and nxpwifi_cfg80211_dump_survey() reads it as soon as user space asks for survey data. For the entries no scan has filled in, a non-zero cca_scan_dur passes the validity check and stale bytes are reported to user space as noise, time and time_busy. Use kcalloc() instead. The array holds two entries per supported channel, small enough not to need vmalloc(), and the two callers change to kfree() accordingly. mwifiex fixed the same issue in commit 0e20450829ca ("wifi: mwifiex: Initialize the chan_stats array to zero"). Fixes: 73b01e57ed3e ("wifi: nxp: add nxpwifi driver for IW61x") Signed-off-by: Linmao Li Reviewed-by: Jeff Chen --- drivers/net/wireless/nxp/nxpwifi/cfg80211.c | 5 +++-- drivers/net/wireless/nxp/nxpwifi/main.c | 4 ++-- 2 files changed, 5 insertions(+), 4 deletions(-) diff --git a/drivers/net/wireless/nxp/nxpwifi/cfg80211.c b/drivers/net/wire= less/nxp/nxpwifi/cfg80211.c index 5cc8cdf594d3e..461e3e1947438 100644 --- a/drivers/net/wireless/nxp/nxpwifi/cfg80211.c +++ b/drivers/net/wireless/nxp/nxpwifi/cfg80211.c @@ -3729,8 +3729,9 @@ int nxpwifi_init_channel_scan_gap(struct nxpwifi_adap= ter *adapter) * additional active scan request for hidden SSIDs on passive channels. */ adapter->num_in_chan_stats =3D 2 * (n_channels_bg + n_channels_a); - adapter->chan_stats =3D vmalloc(array_size(sizeof(*adapter->chan_stats), - adapter->num_in_chan_stats)); + adapter->chan_stats =3D kcalloc(adapter->num_in_chan_stats, + sizeof(*adapter->chan_stats), + GFP_KERNEL); =20 if (!adapter->chan_stats) return -ENOMEM; diff --git a/drivers/net/wireless/nxp/nxpwifi/main.c b/drivers/net/wireless= /nxp/nxpwifi/main.c index b4c63829024a0..c5d078bb45983 100644 --- a/drivers/net/wireless/nxp/nxpwifi/main.c +++ b/drivers/net/wireless/nxp/nxpwifi/main.c @@ -644,7 +644,7 @@ static int _nxpwifi_fw_dpc(const struct firmware *firmw= are, void *context) goto done; =20 err_add_intf: - vfree(adapter->chan_stats); + kfree(adapter->chan_stats); err_init_chan_scan: wiphy_unregister(adapter->wiphy); wiphy_free(adapter->wiphy); @@ -1384,7 +1384,7 @@ static void nxpwifi_uninit_sw(struct nxpwifi_adapter = *adapter) wiphy_free(adapter->wiphy); adapter->wiphy =3D NULL; =20 - vfree(adapter->chan_stats); + kfree(adapter->chan_stats); nxpwifi_free_cmd_buffers(adapter); } =20 --=20 2.25.1