Re: [PATCH v2] wifi: mac80211: mesh: free pending CSA settings on interface stop

"Nicolas Escande" <[email protected]>
Newsgroups org.kernel.vger.linux-wireless,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
On Tue Aug 25, 2026 at 3:57 PM CEST, Deepanshu Kartikey wrote:
> ifmsh->csa is allocated in ieee80211_mesh_csa_beacon() and normally
> freed in ieee80211_mesh_finish_csa() once the channel switch
> completes. If the mesh interface is stopped while a channel switch
> is still in progress, ifmsh->csa is never freed, leaking the
> mesh_csa_settings object.
>
> Free it in ieee80211_stop_mesh(), the same way ifmsh->beacon is
> already handled there.
>
> Reported-by: [email protected]
> Closes: https://syzkaller.appspot.com/bug?extid=f5752cd6b94fe38be666
> Link: https://lore.kernel.org/all/[email protected]/T/ [v1]
> Signed-off-by: Deepanshu Kartikey <[email protected]>
> ---
> v2: drop unnecessary NULL check around csa, kfree_rcu() already
>     handles a NULL pointer (Nicolas Escande)
> ---
>  net/mac80211/mesh.c | 6 ++++++
>  1 file changed, 6 insertions(+)
>
> diff --git a/net/mac80211/mesh.c b/net/mac80211/mesh.c
> index d4507e4e6ec1..48015dcb7add 100644
> --- a/net/mac80211/mesh.c
> +++ b/net/mac80211/mesh.c
> @@ -1201,6 +1201,7 @@ void ieee80211_stop_mesh(struct ieee80211_sub_if_data *sdata)
>  	struct ieee80211_local *local = sdata->local;
>  	struct ieee80211_if_mesh *ifmsh = &sdata->u.mesh;
>  	struct beacon_data *bcn;
> +	struct mesh_csa_settings *csa;
>  
>  	netif_carrier_off(sdata->dev);
>  
> @@ -1222,6 +1223,11 @@ void ieee80211_stop_mesh(struct ieee80211_sub_if_data *sdata)
>  	RCU_INIT_POINTER(ifmsh->beacon, NULL);
>  	kfree_rcu(bcn, rcu_head);
>  
> +	/* free any pending, unfinished channel switch */
> +	csa = sdata_dereference(ifmsh->csa, sdata);
> +	RCU_INIT_POINTER(ifmsh->csa, NULL);
> +	kfree_rcu(csa, rcu_head);
> +
>  	/* free all potentially still buffered group-addressed frames */
>  	local->total_ps_buffered -= skb_queue_len(&ifmsh->ps.bc_buf);
>  	skb_queue_purge(&ifmsh->ps.bc_buf);

Reviewed-by: Nicolas Escande <[email protected]>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.