wifi: nl80211: clean up color-change beacon data on errors

nl80211_color_change() calls nl80211_parse_beacon() for the beacon_next
template, which can allocate params.beacon_next.mbssid_ies and .rnr_ies.
A parsing failure returned directly instead of using the out: cleanup,
leaking any allocations completed before the error.

Allocate the nested attribute table before parsing beacon_next. Its
allocation failure can then return before beacon data exists, while a
later parsing failure uses out: to release the parsed data.

Fixes: dc1e3cb8da ("nl80211: MBSSID and EMA support in AP mode")
Assisted-by: Codex:gpt-5
Assisted-by: Claude:opus-4.8
Assisted-by: Kimi:K3
Signed-off-by: Zhao Li <enderaoelyther@gmail.com>
Link: https://patch.msgid.link/20260731120244.82628-1-enderaoelyther@gmail.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
This commit is contained in:
Zhao Li 2026-07-31 12:02:44 +08:00 committed by Johannes Berg
parent a28fcce6ee
commit 927ee844c4

View File

@ -18928,15 +18928,15 @@ static int nl80211_color_change(struct sk_buff *skb, struct genl_info *info)
if (!wdev->links[params.link_id].ap.beacon_interval)
return -EINVAL;
tb = kzalloc_objs(*tb, NL80211_ATTR_MAX + 1);
if (!tb)
return -ENOMEM;
err = nl80211_parse_beacon(rdev, info->attrs, &params.beacon_next,
wdev->links[params.link_id].ap.chandef.chan,
info->extack);
if (err)
return err;
tb = kzalloc_objs(*tb, NL80211_ATTR_MAX + 1);
if (!tb)
return -ENOMEM;
goto out;
err = nla_parse_nested(tb, NL80211_ATTR_MAX,
info->attrs[NL80211_ATTR_COLOR_CHANGE_ELEMS],