The Infineon Airoc Wi-Fi driver's transmit callback airocmgmtsend() in drivers/wifi/infineon/airocwifi.c allocates a netbuf from the fixed airocpool for every outbound packet. When whdnetworksendethernetdata() returns a synchronous failure, the underlying WHD library does not take ownership of the buffer, but the pre-fix driver returned -EIO without releasing it. Each failed transmit therefore permanently leaks one buffer from the pool.
airocpool is small and fixed (AIROCWIFITXPACKETPOOLCOUNT + AIROCWIFIRXPACKETPOOLCOUNT, default 20 buffers) and is shared by WHD's whdhostbufferget callback for both transmit and receive. Once enough send failures have leaked the pool dry, airocwifihostbufferget() returns WHDBUFFERALLOCFAIL for all subsequent allocations, so both transmit and the WHD-driven receive path fail and Wi-Fi connectivity is lost until the device is rebooted.
The leak occurs only on the transmit error path. A Wi-Fi-adjacent attacker can influence the conditions that cause synchronous send failures (for example by deauthenticating/disassociating the station while the local stack continues to attempt transmits), and ordinary transient failures over the device's lifetime accumulate toward the same state. Reliable on-demand triggering is of high complexity and the impact is availability-only, but the resulting denial of service is permanent and non-recoverable without a reboot.
The fix releases the buffer with airocwifibufferrelease() on the failure branch, returning it to the pool. The commit also removes a redundant ksemgive() in airocmgmtdisconnect(); because data->semacommon is a binary semaphore (limit 1) the duplicate give merely saturated at 1 and had no security impact.