[PATCH net v2] net: microchip: vcap api: Fix possible memory leak in vcap_decode_rule()

From: Abdun Nihaal

Date: Tue Jul 28 2026 - 07:47:35 EST


The memory allocated for struct vcap_rule_internal, keyfields and
actionfields inside vcap_dup_rule() are not freed in some of the error
paths in vcap_decode_rule(). Fix that by calling vcap_free_rule().

Fixes: 610c32b2ce66 ("net: microchip: vcap: Add vcap_get_rule")
Cc: stable@xxxxxxxxxxxxxxx
Reviewed-by: Joe Damato <joe@xxxxxxx>
Signed-off-by: Abdun Nihaal <nihaal@xxxxxxxxxxxxxx>
---
Compile tested only. Issue found using static analysis.

v1->v2:
- Convert the error labels from "err" to "out_err" to avoid confusion
with the err variable, as suggested by Joe Damato.

Link to v1: https://patchwork.kernel.org/project/netdevbpf/patch/20260727125757.134611-1-nihaal@xxxxxxxxxxxxxx/

drivers/net/ethernet/microchip/vcap/vcap_api.c | 9 ++++++---
1 file changed, 6 insertions(+), 3 deletions(-)

diff --git a/drivers/net/ethernet/microchip/vcap/vcap_api.c b/drivers/net/ethernet/microchip/vcap/vcap_api.c
index ff86cde11a32..376be059d662 100644
--- a/drivers/net/ethernet/microchip/vcap/vcap_api.c
+++ b/drivers/net/ethernet/microchip/vcap/vcap_api.c
@@ -2427,18 +2427,21 @@ struct vcap_rule *vcap_decode_rule(struct vcap_rule_internal *elem)

err = vcap_read_rule(ri);
if (err)
- return ERR_PTR(err);
+ goto out_err;

err = vcap_decode_keyset(ri);
if (err)
- return ERR_PTR(err);
+ goto out_err;

err = vcap_decode_actionset(ri);
if (err)
- return ERR_PTR(err);
+ goto out_err;

out:
return &ri->data;
+out_err:
+ vcap_free_rule(&ri->data);
+ return ERR_PTR(err);
}

struct vcap_rule *vcap_get_rule(struct vcap_control *vctrl, u32 id)
--
2.43.0