mirror of
https://github.com/torvalds/linux.git
synced 2026-07-27 17:47:41 +02:00
net: qrtr: fix node refcount leak on ctrl packet alloc failure
qrtr_send_resume_tx() calls qrtr_node_lookup() which takes a reference on the returned node. If the subsequent call to qrtr_alloc_ctrl_packet() fails due to memory allocation failure, the function returns -ENOMEM without calling qrtr_node_release() to release the node reference. Add qrtr_node_release(node) before returning on the allocation failure path to properly release the reference. Signed-off-by: Wentao Liang <vulab@iscas.ac.cn> Reviewed-by: Alexander Lobakin <aleksander.lobakin@intel.com> Reviewed-by: Manivannan Sadhasivam <mani@kernel.org> Link: https://patch.msgid.link/20260528080019.1176700-1-vulab@iscas.ac.cn Signed-off-by: Jakub Kicinski <kuba@kernel.org>
This commit is contained in:
parent
e3c6508a46
commit
3b09ff5411
|
|
@ -1009,8 +1009,10 @@ static int qrtr_send_resume_tx(struct qrtr_cb *cb)
|
|||
return -EINVAL;
|
||||
|
||||
skb = qrtr_alloc_ctrl_packet(&pkt, GFP_KERNEL);
|
||||
if (!skb)
|
||||
if (!skb) {
|
||||
qrtr_node_release(node);
|
||||
return -ENOMEM;
|
||||
}
|
||||
|
||||
pkt->cmd = cpu_to_le32(QRTR_TYPE_RESUME_TX);
|
||||
pkt->client.node = cpu_to_le32(cb->dst_node);
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user