]> www.infradead.org Git - users/dwmw2/linux.git/commitdiff
brcm80211: fix possible memleak in brcmf_proto_msgbuf_attach
authorWang Yufen <wangyufen@huawei.com>
Mon, 20 Jul 2020 09:36:05 +0000 (17:36 +0800)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Fri, 30 Oct 2020 09:38:31 +0000 (10:38 +0100)
[ Upstream commit 6c151410d5b57e6bb0d91a735ac511459539a7bf ]

When brcmf_proto_msgbuf_attach fail and msgbuf->txflow_wq != NULL,
we should destroy the workqueue.

Reported-by: Hulk Robot <hulkci@huawei.com>
Signed-off-by: Wang Yufen <wangyufen@huawei.com>
Signed-off-by: Kalle Valo <kvalo@codeaurora.org>
Link: https://lore.kernel.org/r/1595237765-66238-1-git-send-email-wangyufen@huawei.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
drivers/net/wireless/broadcom/brcm80211/brcmfmac/msgbuf.c

index ee922b0525610e9b355eeb7acb68d9122888de4e..768a99c15c08b4b7dd3dff2d25a78127788caf71 100644 (file)
@@ -1563,6 +1563,8 @@ fail:
                                          BRCMF_TX_IOCTL_MAX_MSG_SIZE,
                                          msgbuf->ioctbuf,
                                          msgbuf->ioctbuf_handle);
+               if (msgbuf->txflow_wq)
+                       destroy_workqueue(msgbuf->txflow_wq);
                kfree(msgbuf);
        }
        return -ENOMEM;