[PATCH net v2 2/2] net: team: free skb when broadcast has no txable port

From: Weiming Shi

Date: Thu Oct 01 2026 - 14:26:49 EST


bc_transmit() sends the original skb through the last txable port.
When no port is txable, it returns false without consuming the skb, but
team_xmit() still returns NETDEV_TX_OK. AF_PACKET sends then retain the
skb and its socket write-memory charge.

A TX-enabled, link-down port keeps the broadcast transmit op installed.
Carrier can stay up through a second link-up, TX-disabled port or be
forced on by userspace. Free the original skb on the no-port path while
leaving the existing drop accounting intact.

Cc: stable@xxxxxxxxxxxxxxx
Fixes: 5fc889911a99 ("team: add broadcast mode")
Assisted-by: LLM
Signed-off-by: Weiming Shi <bestswngs@xxxxxxxxx>
---
drivers/net/team/team_mode_broadcast.c | 2 ++
1 file changed, 2 insertions(+)

diff --git a/drivers/net/team/team_mode_broadcast.c b/drivers/net/team/team_mode_broadcast.c
index 61d7d79f0c363..69dc25a5847a1 100644
--- a/drivers/net/team/team_mode_broadcast.c
+++ b/drivers/net/team/team_mode_broadcast.c
@@ -37,6 +37,8 @@ static bool bc_transmit(struct team *team, struct sk_buff *skb)
ret = !team_dev_queue_xmit(team, last, skb);
if (!sum_ret)
sum_ret = ret;
+ } else {
+ dev_kfree_skb_any(skb);
}
return sum_ret;
}
--
2.55.0