* [PATCH] nvmet: fix refcount leak in nvmet_sq_create()
@ 2026-06-09 9:55 Wentao Liang
2026-06-09 16:44 ` Keith Busch
0 siblings, 1 reply; 2+ messages in thread
From: Wentao Liang @ 2026-06-09 9:55 UTC (permalink / raw)
To: hch, sagi, kch; +Cc: linux-nvme, linux-kernel, Wentao Liang, stable
In nvmet_sq_create(), a reference on the ctrl is taken
via kref_get_unless_zero() before calling nvmet_check_sqid().
If nvmet_check_sqid() fails, the function returns the error
directly without releasing the reference, leading to a leak.
Fix this by jumping to the "ctrl_put" label, which already
performs the necessary nvmet_ctrl_put(ctrl). This ensures the
reference is properly released on this error path.
Cc: stable@vger.kernel.org
Fixes: 1eb380caf527 ("nvmet: Introduce nvmet_sq_create() and nvmet_cq_create()")
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
---
drivers/nvme/target/core.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/nvme/target/core.c b/drivers/nvme/target/core.c
index 62dd59b9aa4f..4477c4d6b1ee 100644
--- a/drivers/nvme/target/core.c
+++ b/drivers/nvme/target/core.c
@@ -944,7 +944,7 @@ u16 nvmet_sq_create(struct nvmet_ctrl *ctrl, struct nvmet_sq *sq,
status = nvmet_check_sqid(ctrl, sqid, true);
if (status != NVME_SC_SUCCESS)
- return status;
+ goto ctrl_put;
ret = nvmet_sq_init(sq, cq);
if (ret) {
--
2.34.1
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: [PATCH] nvmet: fix refcount leak in nvmet_sq_create()
2026-06-09 9:55 [PATCH] nvmet: fix refcount leak in nvmet_sq_create() Wentao Liang
@ 2026-06-09 16:44 ` Keith Busch
0 siblings, 0 replies; 2+ messages in thread
From: Keith Busch @ 2026-06-09 16:44 UTC (permalink / raw)
To: Wentao Liang; +Cc: hch, sagi, kch, linux-nvme, linux-kernel, stable
On Tue, Jun 09, 2026 at 09:55:05AM +0000, Wentao Liang wrote:
> In nvmet_sq_create(), a reference on the ctrl is taken
> via kref_get_unless_zero() before calling nvmet_check_sqid().
> If nvmet_check_sqid() fails, the function returns the error
> directly without releasing the reference, leading to a leak.
>
> Fix this by jumping to the "ctrl_put" label, which already
> performs the necessary nvmet_ctrl_put(ctrl). This ensures the
> reference is properly released on this error path.
Thanks, applied to nvme-7.2.
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-06-09 16:44 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-06-09 9:55 [PATCH] nvmet: fix refcount leak in nvmet_sq_create() Wentao Liang
2026-06-09 16:44 ` Keith Busch
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®