[PATCH wireless] wifi: nxpwifi: fix NULL deref and leak in authenticate
From: techyminati
Date: Thu Oct 01 2026 - 12:31:23 EST
From: Aryan Sinha <sinha.aryan03@xxxxxxxxx>
mgmt is allocated but never checked, and the auth frame is filled in
right after, so a failed kzalloc ends up dereferencing NULL. The skb
error path also returns without freeing mgmt.
Hence, Check the allocation, and free mgmt when the skb alloc fails.
Fixes: 73b01e57ed3e ("wifi: nxp: add nxpwifi driver for IW61x")
Signed-off-by: Aryan Sinha <sinha.aryan03@xxxxxxxxx>
---
drivers/net/wireless/nxp/nxpwifi/cfg80211.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/net/wireless/nxp/nxpwifi/cfg80211.c b/drivers/net/wireless/nxp/nxpwifi/cfg80211.c
index 86304ea33..9eb809caa 100644
--- a/drivers/net/wireless/nxp/nxpwifi/cfg80211.c
+++ b/drivers/net/wireless/nxp/nxpwifi/cfg80211.c
@@ -3403,6 +3403,8 @@ nxpwifi_cfg80211_authenticate(struct wiphy *wiphy,
pkt_len -= 4;
mgmt = kzalloc(pkt_len, GFP_KERNEL);
+ if (!mgmt)
+ return -ENOMEM;
skb = dev_alloc_skb(NXPWIFI_MIN_DATA_HEADER_LEN +
NXPWIFI_MGMT_FRAME_HEADER_SIZE +
@@ -3410,6 +3412,7 @@ nxpwifi_cfg80211_authenticate(struct wiphy *wiphy,
if (!skb) {
nxpwifi_dbg(adapter, ERROR,
"allocate skb failed for management frame\n");
+ kfree(mgmt);
return -ENOMEM;
}
--
2.46.0