All of lore.kernel.org
 help / color / mirror / Atom feed
From: Yi Cong <cong.yi@linux.dev>
To: gregkh@linuxfoundation.org
Cc: linux-staging@lists.linux.dev, linux-wireless@vger.kernel.org,
	linux-kernel@vger.kernel.org, Yi Cong <yicong@kylinos.cn>
Subject: [PATCH 1/4] staging: rtl8723bs: free HalData with vfree, not kfree
Date: Wed, 29 Jul 2026 10:25:06 +0800	[thread overview]
Message-ID: <20260729022509.2863634-2-cong.yi@linux.dev> (raw)
In-Reply-To: <20260729022509.2863634-1-cong.yi@linux.dev>

From: Yi Cong <yicong@kylinos.cn>

In the probe error path of rtw_sdio_if1_init(), HalData is released with
kfree(), but it is allocated with vzalloc() in rtw_hal_data_init(). Freeing
a vmalloc allocation with kfree() is undefined behaviour and can corrupt
the allocator.

Use rtw_hal_data_deinit() instead, which calls vfree() and is the matching
deallocator used on the normal tear-down path. It also NULLs the pointer
and clears hal_data_sz, making it safe to call here.

Fixes: 554c0a3abf21 ("staging: Add rtl8723bs sdio wifi driver")
Signed-off-by: Yi Cong <yicong@kylinos.cn>
---
 drivers/staging/rtl8723bs/os_dep/sdio_intf.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/staging/rtl8723bs/os_dep/sdio_intf.c b/drivers/staging/rtl8723bs/os_dep/sdio_intf.c
index c43a0391a5ca..f7ec09310ce9 100644
--- a/drivers/staging/rtl8723bs/os_dep/sdio_intf.c
+++ b/drivers/staging/rtl8723bs/os_dep/sdio_intf.c
@@ -286,7 +286,7 @@ static struct adapter *rtw_sdio_if1_init(struct dvobj_priv *dvobj, const struct
 
 free_hal_data:
 	if (status != _SUCCESS && padapter->HalData)
-		kfree(padapter->HalData);
+		rtw_hal_data_deinit(padapter);
 
 	if (status != _SUCCESS) {
 		rtw_wdev_unregister(padapter->rtw_wdev);
-- 
2.25.1


  reply	other threads:[~2026-07-29  2:26 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-29  2:25 [PATCH 0/4] staging: rtl8723bs: fix several memory-safety bugs Yi Cong
2026-07-29  2:25 ` Yi Cong [this message]
2026-07-29  2:25 ` [PATCH 2/4] staging: rtl8723bs: fix double free when register_netdev() fails Yi Cong
2026-07-29  5:31   ` Dan Carpenter
2026-07-29  2:25 ` [PATCH 3/4] staging: rtl8723bs: fix NULL deref in c2h_wk_callback() on alloc failure Yi Cong
2026-07-29  2:25 ` [PATCH 4/4] staging: rtl8723bs: fix NULL deref on bcmc station lookup in defrag path Yi Cong

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260729022509.2863634-2-cong.yi@linux.dev \
    --to=cong.yi@linux.dev \
    --cc=gregkh@linuxfoundation.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-staging@lists.linux.dev \
    --cc=linux-wireless@vger.kernel.org \
    --cc=yicong@kylinos.cn \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.