[PATCH net] net: ethernet: i825xx: Fix dma_alloc_coherent() size

From: Thomas Fourier

Date: Tue Oct 06 2026 - 10:36:13 EST


In sni_82596_probe(), the lp->dma buffer is allocated with
dma_alloc_coherent() and with size sizeof(struct i596_dma), and possibly
freed in the error path with the same size. However, in
sni_82596_driver_remove(), the same buffer is freed but with size
sizeof(struct i596_private). This error may leave the freed buffers
mapped, leaking a resource and allowing the device to access freed
memory.

Change the length in sni_82596_driver_remove() to
sizeof(struct i596_dma).

This patch was compile tested only, and found by hand.

Fixes: f2ec8030085a ("Ethernet driver for EISA only SNI RM200/RM400 machines")
Cc: <stable@xxxxxxxxxxxxxxx>
Signed-off-by: Thomas Fourier <fourier.thomas@xxxxxxxxx>
---
drivers/net/ethernet/i825xx/sni_82596.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/net/ethernet/i825xx/sni_82596.c b/drivers/net/ethernet/i825xx/sni_82596.c
index baa598988f47..73e1e153cb78 100644
--- a/drivers/net/ethernet/i825xx/sni_82596.c
+++ b/drivers/net/ethernet/i825xx/sni_82596.c
@@ -159,7 +159,7 @@ static void sni_82596_driver_remove(struct platform_device *pdev)
struct i596_private *lp = netdev_priv(dev);

unregister_netdev(dev);
- dma_free_coherent(&pdev->dev, sizeof(struct i596_private), lp->dma,
+ dma_free_coherent(&pdev->dev, sizeof(struct i596_dma), lp->dma,
lp->dma_addr);
iounmap(lp->ca);
iounmap(lp->mpu_port);
--
2.43.0