]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
qlcnic: fix memory leak in qlcnic_sriov_channel_cfg_cmd()
authorAbdun Nihaal <abdun.nihaal@gmail.com>
Mon, 12 May 2025 04:48:27 +0000 (10:18 +0530)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 4 Jun 2025 12:36:57 +0000 (14:36 +0200)
[ Upstream commit 9d8a99c5a7c7f4f7eca2c168a4ec254409670035 ]

In one of the error paths in qlcnic_sriov_channel_cfg_cmd(), the memory
allocated in qlcnic_sriov_alloc_bc_mbx_args() for mailbox arguments is
not freed. Fix that by jumping to the error path that frees them, by
calling qlcnic_free_mbx_args(). This was found using static analysis.

Fixes: f197a7aa6288 ("qlcnic: VF-PF communication channel implementation")
Signed-off-by: Abdun Nihaal <abdun.nihaal@gmail.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20250512044829.36400-1-abdun.nihaal@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
drivers/net/ethernet/qlogic/qlcnic/qlcnic_sriov_common.c

index 256b19f68caed01899f7b7e7e571e2c3b6a3b0a7..bf510d3882cf1c0e23e98ba00fabef17cfa5cb2c 100644 (file)
@@ -1485,8 +1485,11 @@ static int qlcnic_sriov_channel_cfg_cmd(struct qlcnic_adapter *adapter, u8 cmd_o
        }
 
        cmd_op = (cmd.rsp.arg[0] & 0xff);
-       if (cmd.rsp.arg[0] >> 25 == 2)
-               return 2;
+       if (cmd.rsp.arg[0] >> 25 == 2) {
+               ret = 2;
+               goto out;
+       }
+
        if (cmd_op == QLCNIC_BC_CMD_CHANNEL_INIT)
                set_bit(QLC_BC_VF_STATE, &vf->state);
        else