Re: [PATCH wireless 1/1] wifi: brcmfmac: fix P2P device removal race in brcmf_detach()

From: Arend van Spriel

Date: Sun Oct 04 2026 - 08:30:13 EST


On 9/24/2026 2:30 PM, Michele Dionisio wrote:
> When the driver is removed while the user space process that created
> the P2P device (e.g. wpa_supplicant) is still exiting, the P2P device
> interface is removed twice and the kernel crashes.

[...]

> For the interface without a netdev (the P2P device), take RTNL and the
> wiphy mutex in brcmf_detach() before reading iflist, and remove it with
> locked=true. If brcmf_p2p_del_vif() runs first, brcmf_detach() finds the
> slot empty. If brcmf_detach() runs first, nl80211 does not find the wdev
> any more. The interfaces with a netdev are removed as before, because
> brcmf_del_if() takes RTNL on its own for the primary interface.
>
> Fixes: 9831bcb987df ("brcmfmac: Deleting of p2p device is leaking memory.")
> Cc: stable@xxxxxxxxxxxxxxx
> Assisted-by: claude-opus-5-5

Acked-by: Arend van Spriel <arend.vanspriel@xxxxxxxxxxxx>

> Signed-off-by: Michele Dionisio <michele.dionisio@xxxxxxxxx>