Linux kernel mirror (for testing) git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
kernel os linux

pinctrl: single: fix refcount leak in pcs_add_gpio_func()

of_parse_phandle_with_args() returns a device_node pointer with refcount
incremented in gpiospec.np. The loop iterates through all phandles but
never releases the reference, causing a refcount leak on each iteration.

Add of_node_put() calls to release the reference after extracting the
needed arguments and on the error path when devm_kzalloc() fails.

This bug was detected by our static analysis tool and verified by my
code review.

Fixes: a1a277eb76b3 ("pinctrl: single: create new gpio function range")
Signed-off-by: Wei Li <unsw.weili@gmail.com>
Signed-off-by: Linus Walleij <linusw@kernel.org>

authored by

Wei Li and committed by
Linus Walleij
35335330 e56aa18e

+2
+2
drivers/pinctrl/pinctrl-single.c
··· 1359 1359 } 1360 1360 range = devm_kzalloc(pcs->dev, sizeof(*range), GFP_KERNEL); 1361 1361 if (!range) { 1362 + of_node_put(gpiospec.np); 1362 1363 ret = -ENOMEM; 1363 1364 break; 1364 1365 } ··· 1369 1368 mutex_lock(&pcs->mutex); 1370 1369 list_add_tail(&range->node, &pcs->gpiofuncs); 1371 1370 mutex_unlock(&pcs->mutex); 1371 + of_node_put(gpiospec.np); 1372 1372 } 1373 1373 return ret; 1374 1374 }