[PATCH] soc: qcom: wcnss: fix leak of fw
From: Rosen Penev
Date: Tue Apr 07 2026 - 18:15:42 EST
The kzalloc_flex call needs to release it, not just blindly return.
Also move kfree up as it is allocated after fw.
Reported-by: kernel test robot <lkp@xxxxxxxxx>
Reported-by: Dan Carpenter <error27@xxxxxxxxx>
Closes: https://lore.kernel.org/r/202604060902.awXdPsBh-lkp@xxxxxxxxx/
Signed-off-by: Rosen Penev <rosenp@xxxxxxxxx>
---
drivers/soc/qcom/wcnss_ctrl.c | 11 +++++++----
1 file changed, 7 insertions(+), 4 deletions(-)
diff --git a/drivers/soc/qcom/wcnss_ctrl.c b/drivers/soc/qcom/wcnss_ctrl.c
index ffb31a049d4a..942e11feba65 100644
--- a/drivers/soc/qcom/wcnss_ctrl.c
+++ b/drivers/soc/qcom/wcnss_ctrl.c
@@ -221,8 +221,10 @@ static int wcnss_download_nv(struct wcnss_ctrl *wcnss, bool *expect_cbc)
left = fw->size;
req = kzalloc_flex(*req, fragment, NV_FRAGMENT_SIZE);
- if (!req)
- return -ENOMEM;
+ if (!req) {
+ ret = -ENOMEM;
+ goto release_fw;
+ }
req->frag_size = NV_FRAGMENT_SIZE;
req->hdr.type = WCNSS_DOWNLOAD_NV_REQ;
@@ -243,7 +245,7 @@ static int wcnss_download_nv(struct wcnss_ctrl *wcnss, bool *expect_cbc)
ret = rpmsg_send(wcnss->channel, req, req->hdr.len);
if (ret < 0) {
dev_err(dev, "failed to send smd packet\n");
- goto release_fw;
+ goto release_req;
}
/* Increment for next fragment */
@@ -262,9 +264,10 @@ static int wcnss_download_nv(struct wcnss_ctrl *wcnss, bool *expect_cbc)
ret = 0;
}
+release_req:
+ kfree(req);
release_fw:
release_firmware(fw);
- kfree(req);
return ret;
}
--
2.53.0