]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
wifi: ath10k: fix skb leak on incomplete msdu during rx pop
authorManikanta Pubbisetty <manikanta.pubbisetty@oss.qualcomm.com>
Tue, 23 Jun 2026 06:43:55 +0000 (12:13 +0530)
committerJeff Johnson <jeff.johnson@oss.qualcomm.com>
Thu, 9 Jul 2026 14:44:42 +0000 (07:44 -0700)
When ath10k_htt_rx_pop_paddr32_list() or
ath10k_htt_rx_pop_paddr64_list() encounters an incomplete frame
(RX_ATTENTION_FLAGS_MSDU_DONE not set), it returns -EIO without
purging the skb list built up so far, leaking any skbs already
queued in the list.

Other early-exit paths within these same functions already call
__skb_queue_purge() before returning an error. Add it before the
-EIO return as well to be consistent and prevent the leak.

Tested-on: WCN3990 hw1.0 WLAN.HL.3.2.2.c10-00754-QCAHLSWMTPL-1

Fixes: c545070e404b ("ath10k: implement rx reorder support")
Fixes: 3b0b55b19d1d ("ath10k: Add support for 64 bit HTT in-order indication msg")
Signed-off-by: Manikanta Pubbisetty <manikanta.pubbisetty@oss.qualcomm.com>
Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com>
Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
Link: https://patch.msgid.link/20260623064355.1876743-1-manikanta.pubbisetty@oss.qualcomm.com
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
drivers/net/wireless/ath/ath10k/htt_rx.c

index faac359aa9acb11b39700b62b9b9e68f58614bc9..b3f1b71867213dd56a559b0f182ef5d600711084 100644 (file)
@@ -706,6 +706,7 @@ static int ath10k_htt_rx_pop_paddr32_list(struct ath10k_htt *htt,
                        if (!(__le32_to_cpu(rxd_attention->flags) &
                              RX_ATTENTION_FLAGS_MSDU_DONE)) {
                                ath10k_warn(htt->ar, "tried to pop an incomplete frame, oops!\n");
+                               __skb_queue_purge(list);
                                return -EIO;
                        }
                }
@@ -770,6 +771,7 @@ static int ath10k_htt_rx_pop_paddr64_list(struct ath10k_htt *htt,
                        if (!(__le32_to_cpu(rxd_attention->flags) &
                              RX_ATTENTION_FLAGS_MSDU_DONE)) {
                                ath10k_warn(htt->ar, "tried to pop an incomplete frame, oops!\n");
+                               __skb_queue_purge(list);
                                return -EIO;
                        }
                }