mirror of
https://github.com/torvalds/linux.git
synced 2026-10-10 04:18:03 +02:00
net: usb: lan78xx: Fix URB reference leak in lan78xx_submit_deferred_urbs()
usb_get_from_anchor() hands over a reference to the URB, which the caller
must release. lan78xx_submit_deferred_urbs() never does, so every deferred
Tx URB keeps an extra reference: the counter grows on each suspend/resume
cycle and the URBs are never freed when the buffers are released. Drop
the reference after submitting, and on the path that drops the packet
instead of submitting it.
Fixes: 5f4cc6e251 ("lan78xx: Fix race conditions in suspend/resume handling")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Link: https://patch.msgid.link/20260917115811.2150119-1-vulab@iscas.ac.cn
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
This commit is contained in:
parent
9892d71cf0
commit
17741334d0
|
|
@ -5239,10 +5239,12 @@ static bool lan78xx_submit_deferred_urbs(struct lan78xx_net *dev)
|
|||
!netif_carrier_ok(dev->net) ||
|
||||
pipe_halted) {
|
||||
lan78xx_release_tx_buf(dev, skb);
|
||||
usb_put_urb(urb);
|
||||
continue;
|
||||
}
|
||||
|
||||
ret = usb_submit_urb(urb, GFP_ATOMIC);
|
||||
usb_put_urb(urb);
|
||||
|
||||
if (ret == 0) {
|
||||
netif_trans_update(dev->net);
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user