[PATCH] nfc: st-nci: Fix potential memory leak llt_ndlc_send_queue()
Abdun Nihaal <[email protected]> Tue, 7 Jul 2026 17:14:08 +0530
| Newsgroups | dev.linux.lists.oe-linux-nfc,org.kernel.vger.linux-kernel,org.kernel.vger.stable |
|---|---|
| Message-ID | <[email protected]> |
The skb dequeued from the ndlc->send_q is dropped without freeing or
queueing it back to the send_q. The two function targets of
ndlc->ops->write : st_nci_i2c_write() and st_nci_spi_write() don't alter
or free the skb on error. Fix this by queueing back the skb into the
head of send_q to be processed again later.
Fixes: 35630df68d60 ("NFC: st21nfcb: Add driver for STMicroelectronics ST21NFCB NFC chip")
Cc: [email protected]
Signed-off-by: Abdun Nihaal <[email protected]>
---
Compile tested only. Issue found using static analysis.
drivers/nfc/st-nci/ndlc.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/nfc/st-nci/ndlc.c b/drivers/nfc/st-nci/ndlc.c
index be4808859cfa..480a30acd996 100644
--- a/drivers/nfc/st-nci/ndlc.c
+++ b/drivers/nfc/st-nci/ndlc.c
@@ -101,6 +101,7 @@ static void llt_ndlc_send_queue(struct llt_ndlc *ndlc)
r = ndlc->ops->write(ndlc->phy_id, skb);
if (r < 0) {
ndlc->hard_fault = r;
+ skb_queue_head(&ndlc->send_q, skb);
break;
}
time_sent = jiffies;
--
2.43.0