Re: [PATCH] staging: rtl8723bs: fix xmit_frame/xmit_buf leaks on mgnt-frame error paths

From: Dan Carpenter

Date: Wed Jul 15 2026 - 06:40:10 EST


On Tue, Jul 14, 2026 at 11:35:25PM +0700, Cong Nguyen wrote:
> issue_beacon(), issue_probersp() and issue_asocrsp() obtain a management
> xmit_frame together with its xmit_buf from the driver's fixed-size
> management-TX pools via alloc_mgtxmitframe(). On the normal path the frame
> is handed to dump_mgntframe(), which transfers ownership and eventually
> returns both objects to their pools (the frame and, for beacons, the buf
> in rtl8723bs_mgnt_xmit(); other bufs via the pending-xmitbuf/TX-completion
> path).
>
> Several error/edge paths return early after a successful
> alloc_mgtxmitframe() but before dump_mgntframe(), so ownership is never
> transferred and neither object is freed:
>
> - issue_beacon(): beacon larger than 512 bytes
> - issue_probersp(): cur_network->ie_length > MAX_IE_SZ
> - issue_probersp(): kzalloc() of the SSID scratch buffer fails
> - issue_asocrsp(): pkt_type is neither ASSOCRSP nor REASSOCRSP
>
> Because alloc_mgtxmitframe() removes the frame and buf from their free
> lists (list_del_init) without placing them on any pending list, an
> orphaned pair is on no list and referenced by nobody, so it is only
> reclaimed at driver teardown. Repeated hits progressively exhaust the
> management-TX pools until alloc_mgtxmitframe() returns NULL and the
> interface can no longer send beacons or probe/assoc responses.
>
> Free the frame and buffer on these paths, matching the existing correct
> error handling in issue_assocreq().
>
> Signed-off-by: Cong Nguyen <congnt264@xxxxxxxxx>
> ---

Looks reasonable. Please add a Fixes tag.

Reviewed-by: Dan Carpenter <error27@xxxxxxxxx>

regards,
dan carpenter