From: Yi Cong <cong.yi@linux.dev>
To: gregkh@linuxfoundation.org
Cc: linux-staging@lists.linux.dev, linux-wireless@vger.kernel.org,
linux-kernel@vger.kernel.org, Yi Cong <yicong@kylinos.cn>
Subject: [PATCH v2 2/4] staging: rtl8723bs: fix double free when register_netdev() fails
Date: Thu, 30 Jul 2026 13:59:58 +0800 [thread overview]
Message-ID: <20260730060000.1944670-3-cong.yi@linux.dev> (raw)
In-Reply-To: <20260730060000.1944670-1-cong.yi@linux.dev>
From: Yi Cong <yicong@kylinos.cn>
When register_netdev() fails, the error_register_netdev label in
_rtw_drv_register_netdev() frees the adapter and netdev via
rtw_free_drv_sw()/rtw_free_netdev() and then returns _FAIL.
The caller rtw_drv_init(), however, still holds a non-NULL if1 on this
failure path and jumps to free_if1, where rtw_sdio_if1_deinit() invokes
rtw_free_drv_sw() and rtw_free_netdev() again on the same already-freed
objects, resulting in a double free / use-after-free.
Drop the freeing from error_register_netdev and let rtw_sdio_if1_deinit()
perform the tear-down, which is the single owner for this path.
Fixes: 554c0a3abf21 ("staging: Add rtl8723bs sdio wifi driver")
Signed-off-by: Yi Cong <yicong@kylinos.cn>
---
drivers/staging/rtl8723bs/os_dep/os_intfs.c | 14 ++------------
1 file changed, 2 insertions(+), 12 deletions(-)
diff --git a/drivers/staging/rtl8723bs/os_dep/os_intfs.c b/drivers/staging/rtl8723bs/os_dep/os_intfs.c
index f31196f54b3e0..84633a51e2db7 100644
--- a/drivers/staging/rtl8723bs/os_dep/os_intfs.c
+++ b/drivers/staging/rtl8723bs/os_dep/os_intfs.c
@@ -754,7 +754,6 @@ u8 rtw_free_drv_sw(struct adapter *padapter)
static int _rtw_drv_register_netdev(struct adapter *padapter, char *name)
{
- int ret = _SUCCESS;
struct net_device *pnetdev = padapter->pnetdev;
/* alloc netdev name */
@@ -765,19 +764,10 @@ static int _rtw_drv_register_netdev(struct adapter *padapter, char *name)
/* Tell the network stack we exist */
if (register_netdev(pnetdev) != 0) {
- ret = _FAIL;
- goto error_register_netdev;
+ return _FAIL;
}
- return ret;
-
-error_register_netdev:
-
- rtw_free_drv_sw(padapter);
-
- rtw_free_netdev(pnetdev);
-
- return ret;
+ return _SUCCESS;
}
int rtw_drv_register_netdev(struct adapter *if1)
--
2.25.1
next prev parent reply other threads:[~2026-07-30 6:00 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-30 5:59 [PATCH v2 0/4] staging: rtl8723bs: fix several memory-safety bugs Yi Cong
2026-07-30 5:59 ` [PATCH v2 1/4] staging: rtl8723bs: free HalData with vfree, not kfree Yi Cong
2026-07-30 5:59 ` Yi Cong [this message]
2026-07-30 7:38 ` [PATCH v2 2/4] staging: rtl8723bs: fix double free when register_netdev() fails Greg KH
2026-07-30 5:59 ` [PATCH v2 3/4] staging: rtl8723bs: fix NULL deref in c2h_wk_callback() on alloc failure Yi Cong
2026-07-30 6:00 ` [PATCH v2 4/4] staging: rtl8723bs: fix NULL deref on bcmc station lookup in defrag path Yi Cong
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260730060000.1944670-3-cong.yi@linux.dev \
--to=cong.yi@linux.dev \
--cc=gregkh@linuxfoundation.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-staging@lists.linux.dev \
--cc=linux-wireless@vger.kernel.org \
--cc=yicong@kylinos.cn \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.