Commit 4c81829e authored by Jose Ignacio Tornos Martinez's avatar Jose Ignacio Tornos Martinez Committed by Xiongfeng Wang
Browse files

wifi: ath12k: fix warning when unbinding

stable inclusion
from stable-v6.6.64
commit 223b546c6222d42147eff034433002ca5e2e7e09
category: bugfix
bugzilla: https://gitee.com/src-openeuler/kernel/issues/IBEAF7
CVE: CVE-2024-53191

Reference: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=223b546c6222d42147eff034433002ca5e2e7e09



--------------------------------

commit ca68ce0d9f4bcd032fd1334441175ae399642a06 upstream.

If there is an error during some initialization related to firmware,
the buffers dp->tx_ring[i].tx_status are released.
However this is released again when the device is unbinded (ath12k_pci),
and we get:
WARNING: CPU: 0 PID: 2098 at mm/slub.c:4689 free_large_kmalloc+0x4d/0x80
Call Trace:
free_large_kmalloc
ath12k_dp_free
ath12k_core_deinit
ath12k_pci_remove
...

The issue is always reproducible from a VM because the MSI addressing
initialization is failing.

In order to fix the issue, just set the buffers to NULL after releasing in
order to avoid the double free.

cc: stable@vger.kernel.org
Fixes: d8899132 ("wifi: ath12k: driver for Qualcomm Wi-Fi 7 devices")
Signed-off-by: default avatarJose Ignacio Tornos Martinez <jtornosm@redhat.com>
Link: https://patch.msgid.link/20241017181004.199589-3-jtornosm@redhat.com


Signed-off-by: default avatarJeff Johnson <quic_jjohnson@quicinc.com>
Signed-off-by: default avatarGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: default avatarXiongfeng Wang <wangxiongfeng2@huawei.com>
parent 604e996d
Loading
Loading
Loading
Loading
+3 −1
Original line number Diff line number Diff line
@@ -1249,8 +1249,10 @@ void ath12k_dp_free(struct ath12k_base *ab)

	ath12k_dp_rx_reo_cmd_list_cleanup(ab);

	for (i = 0; i < ab->hw_params->max_tx_ring; i++)
	for (i = 0; i < ab->hw_params->max_tx_ring; i++) {
		kfree(dp->tx_ring[i].tx_status);
		dp->tx_ring[i].tx_status = NULL;
	}

	ath12k_dp_rx_free(ab);
	/* Deinit any SOC level resource */