[PATCH net] net: ethernet: i825xx: Fix dma_alloc_coherent() size
From: Thomas Fourier
Date: Tue Oct 06 2026 - 10:36:13 EST
In sni_82596_probe(), the lp->dma buffer is allocated with
dma_alloc_coherent() and with size sizeof(struct i596_dma), and possibly
freed in the error path with the same size. However, in
sni_82596_driver_remove(), the same buffer is freed but with size
sizeof(struct i596_private). This error may leave the freed buffers
mapped, leaking a resource and allowing the device to access freed
memory.
Change the length in sni_82596_driver_remove() to
sizeof(struct i596_dma).
This patch was compile tested only, and found by hand.
Fixes: f2ec8030085a ("Ethernet driver for EISA only SNI RM200/RM400 machines")
Cc: <stable@xxxxxxxxxxxxxxx>
Signed-off-by: Thomas Fourier <fourier.thomas@xxxxxxxxx>
---
drivers/net/ethernet/i825xx/sni_82596.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/i825xx/sni_82596.c b/drivers/net/ethernet/i825xx/sni_82596.c
index baa598988f47..73e1e153cb78 100644
--- a/drivers/net/ethernet/i825xx/sni_82596.c
+++ b/drivers/net/ethernet/i825xx/sni_82596.c
@@ -159,7 +159,7 @@ static void sni_82596_driver_remove(struct platform_device *pdev)
struct i596_private *lp = netdev_priv(dev);
unregister_netdev(dev);
- dma_free_coherent(&pdev->dev, sizeof(struct i596_private), lp->dma,
+ dma_free_coherent(&pdev->dev, sizeof(struct i596_dma), lp->dma,
lp->dma_addr);
iounmap(lp->ca);
iounmap(lp->mpu_port);
--
2.43.0