From f46b3b235a73999f0dd946c775d225d5077a5a93 Mon Sep 17 00:00:00 2001 From: Pradeep Gurumath Date: Wed, 19 Nov 2025 13:30:11 -0600 Subject: [PATCH] brcmfmac: Fix missing NULL pointer check Issue: Customer identified a missing NULL pointer check and a potential crash/memory leak in brcmf_txfinalize(). Solution: The patch that includes check for NULL pointer Fixes SWWLAN-155248 Signed-off-by: Pradeep Gurumath --- .../broadcom/brcm80211/brcmfmac/core.c | 27 +++++++++++++------ 1 file changed, 19 insertions(+), 8 deletions(-) diff --git a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/core.c b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/core.c index 904398a322b4..dd45e6b78b68 100644 --- a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/core.c +++ b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/core.c @@ -756,16 +756,27 @@ void brcmf_rx_event(struct device *dev, struct sk_buff *skb) void brcmf_txfinalize(struct brcmf_if *ifp, struct sk_buff *txp, bool success) { - struct ethhdr *eh; - u16 type; + if (!txp) { + if (!success && ifp && ifp->ndev) + ifp->ndev->stats.tx_errors++; + return; + } + + if (!ifp) { + brcmu_pkt_buf_free_skb(txp); + return; + } - eh = (struct ethhdr *)(txp->data); - type = ntohs(eh->h_proto); + if (txp->data) { + struct ethhdr *eh = (struct ethhdr *)(txp->data); + u16 type = ntohs(eh->h_proto); - if (type == ETH_P_PAE) { - atomic_dec(&ifp->pend_8021x_cnt); - if (waitqueue_active(&ifp->pend_8021x_wait)) - wake_up(&ifp->pend_8021x_wait); + if (type == ETH_P_PAE) { + atomic_dec(&ifp->pend_8021x_cnt); + /* Adding comment to avoid WARNING */ + if (waitqueue_active(&ifp->pend_8021x_wait)) + wake_up(&ifp->pend_8021x_wait); + } } if (!success && ifp->ndev)