mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] of: Fix phandle_node reference leak in of_map_id()
@ 2026-09-17 12:40 Wentao Liang
  2026-09-30 21:12 ` Rob Herring
  0 siblings, 1 reply; 2+ messages in thread
From: Wentao Liang @ 2026-09-17 12:40 UTC (permalink / raw)
  To: devicetree
  Cc: linux-kernel, maz, robh, robin.murphy, saravanak, will,
	Wentao Liang, stable

of_find_node_by_phandle() returns a node with an elevated reference
count. When the caller passes target == NULL it only wants the
translated ID, so that reference is never handed over and must be
dropped before returning success.

Fixes: 987068fcbdb7 ("of/irq: Break out msi-map lookup (again)")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
---
 drivers/of/base.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/drivers/of/base.c b/drivers/of/base.c
index a650c91897cc..0f548d103037 100644
--- a/drivers/of/base.c
+++ b/drivers/of/base.c
@@ -2201,6 +2201,8 @@ int of_map_id(const struct device_node *np, u32 id,
 
 			if (*target != phandle_node)
 				continue;
+		} else {
+			of_node_put(phandle_node);
 		}
 
 		if (id_out)
-- 
2.34.1


^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-09-30 21:12 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-17 12:40 [PATCH] of: Fix phandle_node reference leak in of_map_id() Wentao Liang
2026-09-30 21:12 ` Rob Herring

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®