diff options
| author | Zhao Li <enderaoelyther@gmail.com> | 2026-07-31 12:02:44 +0800 |
|---|---|---|
| committer | Johannes Berg <johannes.berg@intel.com> | 2026-08-02 18:23:27 +0200 |
| commit | 927ee844c47ac2aef22c8f7a35f098ff576b398b (patch) | |
| tree | a0103fb18012b6ecb146dfa776ca73208b016c23 | |
| parent | a28fcce6ee74be8a4526e6cfa16dc7786d62a784 (diff) | |
| download | linux-next-927ee844c47ac2aef22c8f7a35f098ff576b398b.tar.gz linux-next-927ee844c47ac2aef22c8f7a35f098ff576b398b.zip | |
wifi: nl80211: clean up color-change beacon data on errors
nl80211_color_change() calls nl80211_parse_beacon() for the beacon_next
template, which can allocate params.beacon_next.mbssid_ies and .rnr_ies.
A parsing failure returned directly instead of using the out: cleanup,
leaking any allocations completed before the error.
Allocate the nested attribute table before parsing beacon_next. Its
allocation failure can then return before beacon data exists, while a
later parsing failure uses out: to release the parsed data.
Fixes: dc1e3cb8da8b ("nl80211: MBSSID and EMA support in AP mode")
Assisted-by: Codex:gpt-5
Assisted-by: Claude:opus-4.8
Assisted-by: Kimi:K3
Signed-off-by: Zhao Li <enderaoelyther@gmail.com>
Link: https://patch.msgid.link/20260731120244.82628-1-enderaoelyther@gmail.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
| -rw-r--r-- | net/wireless/nl80211.c | 10 |
1 files changed, 5 insertions, 5 deletions
diff --git a/net/wireless/nl80211.c b/net/wireless/nl80211.c index ac895e02cd41..44f2bad08670 100644 --- a/net/wireless/nl80211.c +++ b/net/wireless/nl80211.c @@ -18928,15 +18928,15 @@ static int nl80211_color_change(struct sk_buff *skb, struct genl_info *info) if (!wdev->links[params.link_id].ap.beacon_interval) return -EINVAL; + tb = kzalloc_objs(*tb, NL80211_ATTR_MAX + 1); + if (!tb) + return -ENOMEM; + err = nl80211_parse_beacon(rdev, info->attrs, ¶ms.beacon_next, wdev->links[params.link_id].ap.chandef.chan, info->extack); if (err) - return err; - - tb = kzalloc_objs(*tb, NL80211_ATTR_MAX + 1); - if (!tb) - return -ENOMEM; + goto out; err = nla_parse_nested(tb, NL80211_ATTR_MAX, info->attrs[NL80211_ATTR_COLOR_CHANGE_ELEMS], |
