From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E48342EEE96 for ; Mon, 10 Aug 2026 19:09:06 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786388948; cv=none; b=ZtCd17N7VGinYPYwDqc71xS2+wqG9/hNo+sLufrlsWh7LXROxsOj4O4RmkiMDbehMw0GJrvvTEWHPdpKijvm7RfKmfTiiQAgHXbjozoUQncp5Nk4+6KXaRQcE4m8YfqpXPtHQwD0Kkvqmkky4YeORP93IUqLrYSfwp5j6zy7O30= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786388948; c=relaxed/simple; bh=13NUffwAFvTle5TtheNyvG1LDrJsnRlC3j+reqguo+c=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=Kx/tnU1Gwq4Z5Zlvew7x5exWFGrnvHvZDR+VPoXxHaNbk9yKtqULZAjj0SD5DFt9/s58BJHx2F7ahfJ7XAQm0kZLopjyyUkW6YtRK7c9o559AEDnGswJLPM8Xp8btIw+/yHI4kiATk3gMHIr7Hu8YT5L/AtlUNWvR6D3UOX2xHU= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=f5BJ7zZP; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="f5BJ7zZP" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 4875D1F000E9; Mon, 10 Aug 2026 19:09:06 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786388946; bh=13NUffwAFvTle5TtheNyvG1LDrJsnRlC3j+reqguo+c=; h=Date:From:To:Cc:Subject:References:In-Reply-To; b=f5BJ7zZPEps1hSew/35/ASJoAspl48P8UGlIGjXyIDYSqBqreVWJkAadN/1YZzkpy pksURFK+7qvVsDYqGNmhDuVt2OkoUut0dTHnDqM5bqLKVNOJD0iytkHVpZVCSsaeDJ O2iW+IXuAf7D3iPi45F8qjSXDHTZfJOJIbOdRWa9tYLD+Rvq6sUbvsE0DFVZHJCMbh 8imb0eAz44Gm2tNkqQzTK61lJ/K8Uau704FbvE3ontT+XzOWqLqtVQybh9lSSUxiyj 1bo2k03zwK+dk4QrnQdi/OHj7VZlzlWrMtYgvjtogxIZ6j/7uG+U03J8iRwK9R+Hv+ nA8WANt3mdjFw== Date: Mon, 10 Aug 2026 13:09:04 -0600 From: Keith Busch To: Jiang HongHui Cc: Justin Tee , Naresh Gottumukkala , Paul Ely , Christoph Hellwig , Sagi Grimberg , Chaitanya Kulkarni , linux-nvme@lists.infradead.org, linux-kernel@vger.kernel.org Subject: Re: [PATCH] nvmet-fc: fix invalid free in LS IOD error path Message-ID: References: <20260729110206.207755-1-jiang_hh2019@163.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20260729110206.207755-1-jiang_hh2019@163.com> On Wed, Jul 29, 2026 at 07:02:06PM +0800, Jiang HongHui wrote: > nvmet_fc_alloc_ls_iodlist() advances iod while initializing the LS IOD > array. If an rqstbuf allocation or response buffer DMA mapping fails, > the unwind loop decrements iod past the start of the array. The final > kfree(iod) therefore frees an address before the allocated object. Thanks, applied to nvme-7.3.