[PATCH] soc: qcom: wcnss_ctrl: fix firmware leak on req allocation failure

From: Felix Gu

Date: Fri Apr 17 2026 - 09:19:05 EST


In wcnss_download_nv(), if kzalloc_flex() fails, the current code
returns -ENOMEM directly and leaves the firmware reference unreleased.

Fixes: 908061f0ad30 ("soc: qcom: wcnss: simplify allocation of req")
Signed-off-by: Felix Gu <ustc.gu@xxxxxxxxx>
---
drivers/soc/qcom/wcnss_ctrl.c | 11 +++++++----
1 file changed, 7 insertions(+), 4 deletions(-)

diff --git a/drivers/soc/qcom/wcnss_ctrl.c b/drivers/soc/qcom/wcnss_ctrl.c
index ffb31a049d4a..f046d0248306 100644
--- a/drivers/soc/qcom/wcnss_ctrl.c
+++ b/drivers/soc/qcom/wcnss_ctrl.c
@@ -221,8 +221,10 @@ static int wcnss_download_nv(struct wcnss_ctrl *wcnss, bool *expect_cbc)
left = fw->size;

req = kzalloc_flex(*req, fragment, NV_FRAGMENT_SIZE);
- if (!req)
- return -ENOMEM;
+ if (!req) {
+ ret = -ENOMEM;
+ goto release_fw;
+ }

req->frag_size = NV_FRAGMENT_SIZE;
req->hdr.type = WCNSS_DOWNLOAD_NV_REQ;
@@ -243,7 +245,7 @@ static int wcnss_download_nv(struct wcnss_ctrl *wcnss, bool *expect_cbc)
ret = rpmsg_send(wcnss->channel, req, req->hdr.len);
if (ret < 0) {
dev_err(dev, "failed to send smd packet\n");
- goto release_fw;
+ goto free_req;
}

/* Increment for next fragment */
@@ -262,9 +264,10 @@ static int wcnss_download_nv(struct wcnss_ctrl *wcnss, bool *expect_cbc)
ret = 0;
}

+free_req:
+ kfree(req);
release_fw:
release_firmware(fw);
- kfree(req);

return ret;
}

---
base-commit: 452c3b1ea875276105ac90ba474f72b4cd9b77a2
change-id: 20260417-wcnss_ctrl-43783099258e

Best regards,
--
Felix Gu <ustc.gu@xxxxxxxxx>