Re: [PATCH v2] wifi: ath11k: fix use after free in ath11k_dp_rx_msdu_coalesce.

Jeff Johnson <[email protected]>
Newsgroups org.infradead.lists.ath11k,org.kernel.vger.linux-wireless
Message-ID <[email protected]>
On 5/5/2026 10:17 AM, Willmar Knikker wrote:
> In ath11k_dp_rx_msdu_coalesce the loop uses ->is_continuation after
> the dev_kfree_skb_any. This can cause a use after free kfence.
> 
> Use flag for caching is_continuation for use after the
> dev_kfree_skb_any.
> 
> Fixes: d5c65159f289 ("ath11k: driver for Qualcomm IEEE 802.11ax devices")
> Signed-off-by: Willmar Knikker <[email protected]>

for future reference the revision history should come after the "---"

https://www.kernel.org/doc/html/latest/process/submitting-patches.html#commentary

no need to re-submit for this; I can clean this up in my branch

> Changes in v2:
>  - add bool _is_continuation for use after the free.
>  - Add Fixes, label to commit.
> ---
>  drivers/net/wireless/ath/ath11k/dp_rx.c | 6 ++++--
>  1 file changed, 4 insertions(+), 2 deletions(-)
> 
> diff --git a/drivers/net/wireless/ath/ath11k/dp_rx.c b/drivers/net/wireless/ath/ath11k/dp_rx.c
> index fe79109adc70..16364f76fc3c 100644
> --- a/drivers/net/wireless/ath/ath11k/dp_rx.c
> +++ b/drivers/net/wireless/ath/ath11k/dp_rx.c
> @@ -1761,6 +1761,7 @@ static int ath11k_dp_rx_msdu_coalesce(struct ath11k *ar,
>  	int buf_first_hdr_len, buf_first_len;
>  	struct hal_rx_desc *ldesc;
>  	int space_extra, rem_len, buf_len;
> +	bool is_continuation;
>  	u32 hal_rx_desc_sz = ar->ab->hw_params.hal_desc_sz;
>  
>  	/* As the msdu is spread across multiple rx buffers,
> @@ -1810,7 +1811,8 @@ static int ath11k_dp_rx_msdu_coalesce(struct ath11k *ar,
>  	rem_len = msdu_len - buf_first_len;
>  	while ((skb = __skb_dequeue(msdu_list)) != NULL && rem_len > 0) {
>  		rxcb = ATH11K_SKB_RXCB(skb);
> -		if (rxcb->is_continuation)
> +		is_continuation = rxcb->is_continuation;
> +		if (is_continuation)
>  			buf_len = DP_RX_BUFFER_SIZE - hal_rx_desc_sz;
>  		else
>  			buf_len = rem_len;
> @@ -1828,7 +1830,7 @@ static int ath11k_dp_rx_msdu_coalesce(struct ath11k *ar,
>  		dev_kfree_skb_any(skb);
>  
>  		rem_len -= buf_len;
> -		if (!rxcb->is_continuation)
> +		if (!is_continuation)
>  			break;
>  	}
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.