]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
wifi: cfg80211: Fix an error handling path in cfg80211_wext_siwscan()
authorChristophe JAILLET <christophe.jaillet@wanadoo.fr>
Sat, 20 Jun 2026 19:48:56 +0000 (21:48 +0200)
committerJohannes Berg <johannes.berg@intel.com>
Mon, 6 Jul 2026 12:11:06 +0000 (14:11 +0200)
If the test against IEEE80211_MAX_SSID_LEN fails, then 'creq' leaks.
Use the existing error handling path to fix it.

Fixes: 2a5193119269 ("cfg80211/nl80211: scanning (and mac80211 update to use it)")
Signed-off-by: Christophe JAILLET <christophe.jaillet@wanadoo.fr>
Link: https://patch.msgid.link/a1be7eea4da0da18f90589af252bb76a18a61978.1781984889.git.christophe.jaillet@wanadoo.fr
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
net/wireless/scan.c

index 05b7dc6b766ce94b5769c5488f02f01061a058e4..38001684014d9497cf69027f9544102120970033 100644 (file)
@@ -3612,8 +3612,10 @@ int cfg80211_wext_siwscan(struct net_device *dev,
        /* translate "Scan for SSID" request */
        if (wreq) {
                if (wrqu->data.flags & IW_SCAN_THIS_ESSID) {
-                       if (wreq->essid_len > IEEE80211_MAX_SSID_LEN)
-                               return -EINVAL;
+                       if (wreq->essid_len > IEEE80211_MAX_SSID_LEN) {
+                               err = -EINVAL;
+                               goto out;
+                       }
                        memcpy(creq->req.ssids[0].ssid, wreq->essid,
                               wreq->essid_len);
                        creq->req.ssids[0].ssid_len = wreq->essid_len;