]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
soc: qcom: wcnss: fix leak of fw
authorRosen Penev <rosenp@gmail.com>
Tue, 7 Apr 2026 22:15:19 +0000 (15:15 -0700)
committerBjorn Andersson <andersson@kernel.org>
Sat, 9 May 2026 15:28:49 +0000 (10:28 -0500)
The kzalloc_flex call needs to release it, not just blindly return.

Also move kfree up as it is allocated after fw.

Reported-by: kernel test robot <lkp@intel.com>
Reported-by: Dan Carpenter <error27@gmail.com>
Closes: https://lore.kernel.org/r/202604060902.awXdPsBh-lkp@intel.com/
Signed-off-by: Rosen Penev <rosenp@gmail.com>
Link: https://lore.kernel.org/r/20260407221519.6824-1-rosenp@gmail.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
drivers/soc/qcom/wcnss_ctrl.c

index ffb31a049d4a922ac197080492b8d447960682b1..942e11feba65dfffaca588ddd2db5d2d7d92d830 100644 (file)
@@ -221,8 +221,10 @@ static int wcnss_download_nv(struct wcnss_ctrl *wcnss, bool *expect_cbc)
        left = fw->size;
 
        req = kzalloc_flex(*req, fragment, NV_FRAGMENT_SIZE);
-       if (!req)
-               return -ENOMEM;
+       if (!req) {
+               ret = -ENOMEM;
+               goto release_fw;
+       }
 
        req->frag_size = NV_FRAGMENT_SIZE;
        req->hdr.type = WCNSS_DOWNLOAD_NV_REQ;
@@ -243,7 +245,7 @@ static int wcnss_download_nv(struct wcnss_ctrl *wcnss, bool *expect_cbc)
                ret = rpmsg_send(wcnss->channel, req, req->hdr.len);
                if (ret < 0) {
                        dev_err(dev, "failed to send smd packet\n");
-                       goto release_fw;
+                       goto release_req;
                }
 
                /* Increment for next fragment */
@@ -262,9 +264,10 @@ static int wcnss_download_nv(struct wcnss_ctrl *wcnss, bool *expect_cbc)
                ret = 0;
        }
 
+release_req:
+       kfree(req);
 release_fw:
        release_firmware(fw);
-       kfree(req);
 
        return ret;
 }