* [PATCH] xen/gntdev: Fix gntdev_dmabuf ref leak in dmabuf_exp_wait_released()
@ 2026-09-16 17:09 Wentao Liang
2026-10-09 8:15 ` Juergen Gross
0 siblings, 1 reply; 2+ messages in thread
From: Wentao Liang @ 2026-09-16 17:09 UTC (permalink / raw)
To: boris.ostrovsky
Cc: jgross, linux-kernel, oleksandr_andrushchenko,
oleksandr_tyshchenko, sstabellini, xen-devel, Wentao Liang,
stable
dmabuf_exp_wait_released() takes a reference on the exported
gntdev_dmabuf with dmabuf_exp_wait_obj_get_dmabuf() and passes it to
dmabuf_exp_wait_obj_new(), which drops that reference after adding the
wait object to the wait list. When the wait object allocation fails,
dmabuf_exp_wait_obj_new() returns ERR_PTR(-ENOMEM) early and the
reference is never dropped, leaking a reference to the exported
gntdev_dmabuf.
Drop the reference on the allocation failure path so the reference is
consumed whether the wait object is created or not.
Fixes: 932d6562179e ("xen/gntdev: Add initial support for dma-buf UAPI")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
---
drivers/xen/gntdev-dmabuf.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/xen/gntdev-dmabuf.c b/drivers/xen/gntdev-dmabuf.c
index 83b0df460894..df1883aca850 100644
--- a/drivers/xen/gntdev-dmabuf.c
+++ b/drivers/xen/gntdev-dmabuf.c
@@ -96,8 +96,10 @@ dmabuf_exp_wait_obj_new(struct gntdev_dmabuf_priv *priv,
struct gntdev_dmabuf_wait_obj *obj;
obj = kzalloc_obj(*obj);
- if (!obj)
+ if (!obj) {
+ kref_put(&gntdev_dmabuf->u.exp.refcount, dmabuf_exp_release);
return ERR_PTR(-ENOMEM);
+ }
init_completion(&obj->completion);
obj->gntdev_dmabuf = gntdev_dmabuf;
--
2.34.1
^ permalink raw reply [flat|nested] 2+ messages in thread* Re: [PATCH] xen/gntdev: Fix gntdev_dmabuf ref leak in dmabuf_exp_wait_released()
2026-09-16 17:09 [PATCH] xen/gntdev: Fix gntdev_dmabuf ref leak in dmabuf_exp_wait_released() Wentao Liang
@ 2026-10-09 8:15 ` Juergen Gross
0 siblings, 0 replies; 2+ messages in thread
From: Juergen Gross @ 2026-10-09 8:15 UTC (permalink / raw)
To: Wentao Liang, boris.ostrovsky
Cc: linux-kernel, oleksandr_andrushchenko, oleksandr_tyshchenko,
sstabellini, xen-devel, stable
[-- Attachment #1.1.1: Type: text/plain, Size: 830 bytes --]
On 16.09.26 19:09, Wentao Liang wrote:
> dmabuf_exp_wait_released() takes a reference on the exported
> gntdev_dmabuf with dmabuf_exp_wait_obj_get_dmabuf() and passes it to
> dmabuf_exp_wait_obj_new(), which drops that reference after adding the
> wait object to the wait list. When the wait object allocation fails,
> dmabuf_exp_wait_obj_new() returns ERR_PTR(-ENOMEM) early and the
> reference is never dropped, leaking a reference to the exported
> gntdev_dmabuf.
>
> Drop the reference on the allocation failure path so the reference is
> consumed whether the wait object is created or not.
>
> Fixes: 932d6562179e ("xen/gntdev: Add initial support for dma-buf UAPI")
> Cc: stable@vger.kernel.org
> Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Reviewed-by: Juergen Gross <jgross@suse.com>
Juergen
[-- Attachment #1.1.2: OpenPGP public key --]
[-- Type: application/pgp-keys, Size: 3743 bytes --]
[-- Attachment #2: OpenPGP digital signature --]
[-- Type: application/pgp-signature, Size: 495 bytes --]
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-10-09 8:15 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-16 17:09 [PATCH] xen/gntdev: Fix gntdev_dmabuf ref leak in dmabuf_exp_wait_released() Wentao Liang
2026-10-09 8:15 ` Juergen Gross
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®