From: Thierry Escande Date: Thu, 15 Nov 2012 17:24:28 +0000 (+0100) Subject: NFC: Fix pn533 target mode memory leak X-Git-Tag: v3.6.9~10 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=288267200ed15a769b2ec0045873c7afdf759d42;p=thirdparty%2Fkernel%2Fstable.git NFC: Fix pn533 target mode memory leak commit 5b412fd11c918171c98a253d8a3484afa9f69ca5 upstream. In target mode, sent sk_buff were not freed in pn533_tm_send_complete Signed-off-by: Thierry Escande Signed-off-by: Samuel Ortiz Signed-off-by: Peter Huewe Signed-off-by: Greg Kroah-Hartman --- diff --git a/drivers/nfc/pn533.c b/drivers/nfc/pn533.c index 413fcad3833c5..ac520406e1346 100644 --- a/drivers/nfc/pn533.c +++ b/drivers/nfc/pn533.c @@ -2014,8 +2014,12 @@ error: static int pn533_tm_send_complete(struct pn533 *dev, void *arg, u8 *params, int params_len) { + struct sk_buff *skb_out = arg; + nfc_dev_dbg(&dev->interface->dev, "%s", __func__); + dev_kfree_skb(skb_out); + if (params_len < 0) { nfc_dev_err(&dev->interface->dev, "Error %d when sending data", @@ -2053,7 +2057,7 @@ static int pn533_tm_send(struct nfc_dev *nfc_dev, struct sk_buff *skb) rc = pn533_send_cmd_frame_async(dev, out_frame, dev->in_frame, dev->in_maxlen, pn533_tm_send_complete, - NULL, GFP_KERNEL); + skb, GFP_KERNEL); if (rc) { nfc_dev_err(&dev->interface->dev, "Error %d when trying to send data", rc);