From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f52.google.com (mail-pj1-f52.google.com [209.85.216.52]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6F1423C1092 for ; Tue, 25 Aug 2026 19:13:46 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.52 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787685227; cv=none; b=nXqXL7767wuxiVoGG8z8+5cAVvgO35cgd6u0vWp+MvCEn7AgVVshHRv+j3VK5pj88TU13p5jbGf4IhImnBjupcg4S+xoyGc31VSIzSl7J54fq9pUI9mEX86toC3qi3tud5SzbP5yyZDJkCCwQZmpi2XwzWcKgUCxOhp8x2KkpwY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787685227; c=relaxed/simple; bh=udMYTs2jhhnqWuzc81j2xeKLhtxmHbck3h18071BzxY=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=Nsdz5jP9kRk8o8QdZ3b72m3ZiKU8wyoz3cjadY1ImfXhddY5X6yolnWz3HXo3jhHUij87GVn9IqXc5Oc0GOo2wIFAzZzW9BUAoiJQ2tEpiroZvyGrPFMECMxb6yRkyMj48HcRir1YcWfMBhHDJscNZeVmXmrefr3m7WKKmGvpB4= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=AY8a0wme; arc=none smtp.client-ip=209.85.216.52 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="AY8a0wme" Received: by mail-pj1-f52.google.com with SMTP id 98e67ed59e1d1-3964e480f76so311995a91.1 for ; Tue, 25 Aug 2026 12:13:46 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787685226; x=1788290026; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=VocCPH5ylV7JwhJHJK0lPlDAU6CMHqHJpIhC1H0Dl8Y=; b=AY8a0wmehLDQsgUdpuwp2EATOjmxBnWjWuFg98OP+sBJHoJBouzmuYzRbQF1LOvG8m eYEXmgkTsXsqufuHbK/zDUjdyqYjqTKDE8DCnY8cB0OWh8e1P5A2+YsBCKoLLulWdJS4 xeBwTYOujbWx6p3TtlZTNyUEr1kfAqgLJp/7ukFTaZpNWRc4DE0RmgW8swQyRuwpIOj7 u9uYpahlk4b1Yg0svpEPNrINx4D4WLyG5QTwlUXFWUUHcladJdXvFTGhi6fKvSILe3Pz vZk4y7nnc0+xSBIcu3PKG/WW+Gb/vT43mvF5pyduIak+5whx1ghMS/BXnRm8CLum3vYq 7+HQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787685226; x=1788290026; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=VocCPH5ylV7JwhJHJK0lPlDAU6CMHqHJpIhC1H0Dl8Y=; b=Mc5Ocagve4W0gFVAYqcEj9TqSAFTSC/oteAiyLb6nzPyKWyPTTZps50q6PFIqaYqLZ PXxXJcoqabAJ6h3U27AyVt9pRUrk7Y8KS3p442JiVWKDvtmvdUyvDXAUeaESCYZun6um Ptk3eJMp3ZkDzQCnexuQ6uOT++vtDRJLKZCht9ZBGw1fGG6DW0pyMA4+DAhWNH3wfc5x lYa1z3ubbL+K+rKi9XFxRuGONAlmCvyZuizuT0iNiVWVqCxgPsfD9Bktre/z60VqwTY1 hbPj1CKMOTdRNFhMkQJsKZYbJx9txVDLCAMD2GfRo0VkOcUPnm8hdYkvp3DgMSe9SMFv LxdA== X-Gm-Message-State: AFuF++m3oefEUXjF0/SjT+76+039h/uEJTOTdyU8ckLbbUAtQS352jR8 NP6ml6sQ7ldMLb9ePnOUs6qabxKE9VI/SNIgyH7eWOcqYPL1qJbRajuj X-Gm-Gg: AR+sD12cPysN991RT7tEq2SI2N3OW95iTQInT9PD5gHGu8dXYtoB9ryS4sSw2Adw7Gl 74mcW7/nY6qhzhSEtCnk8g2qZMixxz986z6OkEbmbz2yckQ7tQJ8xR7/GDqPzvFdJDFEql3dGvJ CnUK+7uMHUTSfvUJjJsyHhuofvcC5hXDC2ISJBchitmVc6NuVFLtphgvUXCs+cxmAZbhSuTbcux 6BTg1oaobvJpNom5HMiNfg+om491lnCrLWud42IH9RxNV7xv3qn6rv1XE7fQ/bomchzKGumZKFL K07W3AAXxlvmYFlG0gcmEvZUNlhIfDm7Z7hUT85jvLsp1IAZfYUjE2VMtmHHNncG3EK3tW28aup xgM1Ej/qvOQCMaxbMLzJsYrem8p+cqArrKl/AqxAYG25MgdqMIsH7Tj5isDKJnqc6+xH4Cz0dh5 +XEO7z0NyeLPgrs5h4pmXMsk2XsvMUBEQIiKMnZIFCEHyKHpmisJ8+216XG52YDuClKg== X-Received: by 2002:a17:90b:388e:b0:396:6344:3b63 with SMTP id 98e67ed59e1d1-3966d364af9mr2691106a91.2.1787685225674; Tue, 25 Aug 2026 12:13:45 -0700 (PDT) Received: from bloom.localdomain ([2604:3d09:178e:e100::6868]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-3966875b967sm843406a91.6.2026.08.25.12.13.43 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 25 Aug 2026 12:13:43 -0700 (PDT) From: Ivy Lopez To: akpm@linux-foundation.org, lasse.collin@tukaani.org Cc: linux-kernel@vger.kernel.org, Ivy Lopez Subject: [PATCH] lib: decompress_unxz: fix memory leak of 'in' buffer in single-call mode Date: Tue, 25 Aug 2026 13:13:33 -0600 Message-ID: <20260825191333.34276-1-skunkolee@gmail.com> X-Mailer: git-send-email 2.55.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit When fill and flush are both NULL (single-call mode), unxz() takes the xz_dec_run() fast path and skips straight to xz_dec_end(s), bypassing the free(in)/free(b.out) cleanup that only runs inside the multi-call (fill/flush) branch. If 'in' was NULL on entry, it gets allocated locally (must_free_in = true) and is never freed on this path, leaking XZ_IOBUF_SIZE bytes on every single-call decompression that doesn't supply its own input buffer. Move the must_free_in/flush cleanup out of the multi-call branch so it runs after both paths. Link: https://bugzilla.kernel.org/show_bug.cgi?id=207113 Signed-off-by: Ivy Lopez --- lib/decompress_unxz.c | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/lib/decompress_unxz.c b/lib/decompress_unxz.c index 05d5cb490a44..9ccded9934c6 100644 --- a/lib/decompress_unxz.c +++ b/lib/decompress_unxz.c @@ -342,13 +342,13 @@ STATIC int INIT unxz(unsigned char *in, long in_size, b.out_pos = 0; } } while (ret == XZ_OK); + } - if (must_free_in) - free(in); + if (must_free_in) + free(in); - if (flush != NULL) - free(b.out); - } + if (flush != NULL) + free(b.out); if (in_used != NULL) *in_used += b.in_pos; -- 2.55.0