mirror of
https://github.com/torvalds/linux.git
synced 2026-09-29 12:24:02 +02:00
Bluetooth: btnxpuart: Fix skb leak in nxp_process_fw_dump()
When CONFIG_DEV_COREDUMP=n, hci_devcd_append() returns -EOPNOTSUPP
without freeing its skb argument. This leaks the cloned skb and also
prevents nxp_set_ind_reset() from being called to perform recovery.
Fix by guarding the hci_devcd_append(hdev, skb_clone(skb, GFP_ATOMIC))
call with IS_ENABLED(CONFIG_DEV_COREDUMP).
Fixes: 998e447f44 ("Bluetooth: btnxpuart: Add support for HCI coredump feature")
Signed-off-by: Zijun Hu <zijun.hu@oss.qualcomm.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
This commit is contained in:
parent
f033482d76
commit
f2bbb36426
|
|
@ -1388,9 +1388,11 @@ static int nxp_process_fw_dump(struct hci_dev *hdev, struct sk_buff *skb)
|
|||
msecs_to_jiffies(20000));
|
||||
}
|
||||
|
||||
err = hci_devcd_append(hdev, skb_clone(skb, GFP_ATOMIC));
|
||||
if (err < 0)
|
||||
goto free_skb;
|
||||
if (IS_ENABLED(CONFIG_DEV_COREDUMP)) {
|
||||
err = hci_devcd_append(hdev, skb_clone(skb, GFP_ATOMIC));
|
||||
if (err < 0)
|
||||
goto free_skb;
|
||||
}
|
||||
|
||||
if (buf_len == 0) {
|
||||
bt_dev_warn(hdev, "==== FW dump complete ===");
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user