Commit 98ddcbe0 authored by Christian Engelmayer's avatar Christian Engelmayer Committed by John W. Linville

rsi: Fix a potential memory leak in rsi_set_channel()

Fix a potential memory leak in function rsi_set_channel() that is used to
program channel changes. The channel check block for the frequency bands
directly exits the function in case of an error, thus leaving an already
allocated skb unreferenced. Move the checks above allocating the skb.
Detected by Coverity: CID 1195576.
Signed-off-by: default avatarChristian Engelmayer <cengelma@gmx.at>
Signed-off-by: default avatarJohn W. Linville <linville@tuxdriver.com>
parent af64dc74
...@@ -841,16 +841,6 @@ int rsi_set_channel(struct rsi_common *common, u16 channel) ...@@ -841,16 +841,6 @@ int rsi_set_channel(struct rsi_common *common, u16 channel)
rsi_dbg(MGMT_TX_ZONE, rsi_dbg(MGMT_TX_ZONE,
"%s: Sending scan req frame\n", __func__); "%s: Sending scan req frame\n", __func__);
skb = dev_alloc_skb(FRAME_DESC_SZ);
if (!skb) {
rsi_dbg(ERR_ZONE, "%s: Failed in allocation of skb\n",
__func__);
return -ENOMEM;
}
memset(skb->data, 0, FRAME_DESC_SZ);
mgmt_frame = (struct rsi_mac_frame *)skb->data;
if (common->band == IEEE80211_BAND_5GHZ) { if (common->band == IEEE80211_BAND_5GHZ) {
if ((channel >= 36) && (channel <= 64)) if ((channel >= 36) && (channel <= 64))
channel = ((channel - 32) / 4); channel = ((channel - 32) / 4);
...@@ -868,6 +858,16 @@ int rsi_set_channel(struct rsi_common *common, u16 channel) ...@@ -868,6 +858,16 @@ int rsi_set_channel(struct rsi_common *common, u16 channel)
} }
} }
skb = dev_alloc_skb(FRAME_DESC_SZ);
if (!skb) {
rsi_dbg(ERR_ZONE, "%s: Failed in allocation of skb\n",
__func__);
return -ENOMEM;
}
memset(skb->data, 0, FRAME_DESC_SZ);
mgmt_frame = (struct rsi_mac_frame *)skb->data;
mgmt_frame->desc_word[0] = cpu_to_le16(RSI_WIFI_MGMT_Q << 12); mgmt_frame->desc_word[0] = cpu_to_le16(RSI_WIFI_MGMT_Q << 12);
mgmt_frame->desc_word[1] = cpu_to_le16(SCAN_REQUEST); mgmt_frame->desc_word[1] = cpu_to_le16(SCAN_REQUEST);
mgmt_frame->desc_word[4] = cpu_to_le16(channel); mgmt_frame->desc_word[4] = cpu_to_le16(channel);
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment