All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] wifi: ath12k: fix channel list double-free on error paths
@ 2026-07-31  9:38 Linkai Gong
  2026-08-07  1:47 ` Jeff Johnson
                   ` (2 more replies)
  0 siblings, 3 replies; 8+ messages in thread
From: Linkai Gong @ 2026-07-31  9:38 UTC (permalink / raw)
  To: Jeff Johnson
  Cc: Vasanthakumar Thiagarajan, Rameshkumar Sundaram, linux-wireless,
	ath12k, linux-kernel, Linkai Gong

ath12k_mac_setup_channels_rates() frees band channel arrays on failure
but either leaves the pointers non-NULL or clears the wrong band. Later
ath12k_mac_cleanup_unregister() frees the same pointers again.

Clear the correct sbands[].channels pointers after kfree(), including
a copy-paste bug that nulled 2 GHz after freeing 6 GHz channels.

Fixes: acc152f9be20 ("wifi: ath12k: combine channel list for split-phy devices in single-wiphy")
Signed-off-by: Linkai Gong <gonglinkai@kylinos.cn>
---
 drivers/net/wireless/ath/ath12k/mac.c | 5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

diff --git a/drivers/net/wireless/ath/ath12k/mac.c b/drivers/net/wireless/ath/ath12k/mac.c
index a0928890671a..5468a8d2d5d5 100644
--- a/drivers/net/wireless/ath/ath12k/mac.c
+++ b/drivers/net/wireless/ath/ath12k/mac.c
@@ -14275,6 +14275,7 @@ static int ath12k_mac_setup_channels_rates(struct ath12k *ar,
 					   sizeof(ath12k_6ghz_channels), GFP_KERNEL);
 			if (!channels) {
 				kfree(ar->mac.sbands[NL80211_BAND_2GHZ].channels);
+				ar->mac.sbands[NL80211_BAND_2GHZ].channels = NULL;
 				return -ENOMEM;
 			}
 
@@ -14325,7 +14326,9 @@ static int ath12k_mac_setup_channels_rates(struct ath12k *ar,
 					   GFP_KERNEL);
 			if (!channels) {
 				kfree(ar->mac.sbands[NL80211_BAND_2GHZ].channels);
+				ar->mac.sbands[NL80211_BAND_2GHZ].channels = NULL;
 				kfree(ar->mac.sbands[NL80211_BAND_6GHZ].channels);
+				ar->mac.sbands[NL80211_BAND_6GHZ].channels = NULL;
 				return -ENOMEM;
 			}
 
@@ -14365,7 +14368,7 @@ static int ath12k_mac_setup_channels_rates(struct ath12k *ar,
 					kfree(ar->mac.sbands[NL80211_BAND_2GHZ].channels);
 					ar->mac.sbands[NL80211_BAND_2GHZ].channels = NULL;
 					kfree(ar->mac.sbands[NL80211_BAND_6GHZ].channels);
-					ar->mac.sbands[NL80211_BAND_2GHZ].channels = NULL;
+					ar->mac.sbands[NL80211_BAND_6GHZ].channels = NULL;
 					kfree(channels);
 					band->channels = NULL;
 					return ret;
-- 
2.25.1


^ permalink raw reply related	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2026-08-11  2:06 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-31  9:38 [PATCH] wifi: ath12k: fix channel list double-free on error paths Linkai Gong
2026-08-07  1:47 ` Jeff Johnson
2026-08-07  2:56   ` Linkai Gong
2026-08-07 15:48     ` Jeff Johnson
2026-08-10  9:37 ` Baochen Qiang
2026-08-11  2:05   ` Linkai Gong
2026-08-10 10:14 ` Rameshkumar Sundaram
2026-08-11  2:06   ` Linkai Gong

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.