[PATCH wireless-next 2/3] wifi: nxpwifi: free the aggregation buffer when the RA list disappears
From: Linmao Li
Date: Thu Aug 13 2026 - 04:24:10 EST
nxpwifi_11n_aggregate_pkt() drops ra_list_spinlock while it copies each
subframe, so it rechecks the RA list after taking the lock again. The
check inside the aggregation loop returns without releasing the
skb_aggr it has been filling, leaking one tx_buf_size buffer along with
the subframes already aggregated into it.
Release skb_aggr there, the way the same check on the -EBUSY path
already does.
mwifiex fixed the same issue in commit 990a73dec3fd ("wifi: mwifiex: Fix
memory leak in mwifiex_11n_aggregate_pkt()").
Fixes: 73b01e57ed3e ("wifi: nxp: add nxpwifi driver for IW61x")
Signed-off-by: Linmao Li <lilinmao@xxxxxxxxxx>
---
drivers/net/wireless/nxp/nxpwifi/11n_aggr.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/net/wireless/nxp/nxpwifi/11n_aggr.c b/drivers/net/wireless/nxp/nxpwifi/11n_aggr.c
index be7080f2a6ce7..54933c42c960d 100644
--- a/drivers/net/wireless/nxp/nxpwifi/11n_aggr.c
+++ b/drivers/net/wireless/nxp/nxpwifi/11n_aggr.c
@@ -168,6 +168,7 @@ nxpwifi_11n_aggregate_pkt(struct nxpwifi_private *priv,
if (!nxpwifi_is_ralist_valid(priv, pra_list, ptrindex)) {
spin_unlock_bh(&priv->wmm.ra_list_spinlock);
+ nxpwifi_write_data_complete(adapter, skb_aggr, 1, -1);
return -ENOENT;
}
--
2.25.1