]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
ACPICA: Fix memory leak if acpi_ps_get_next_namepath() fails
authorArmin Wolf <W_Armin@gmx.de>
Wed, 3 Apr 2024 18:50:11 +0000 (20:50 +0200)
committerRafael J. Wysocki <rafael.j.wysocki@intel.com>
Thu, 29 Aug 2024 15:56:06 +0000 (17:56 +0200)
ACPICA commit 2802af722bbde7bf1a7ac68df68e179e2555d361

If acpi_ps_get_next_namepath() fails, the previously allocated
union acpi_parse_object needs to be freed before returning the
status code.

The issue was first being reported on the Linux ACPI mailing list:

Link: https://lore.kernel.org/linux-acpi/56f94776-484f-48c0-8855-dba8e6a7793b@yandex.ru/T/
Link: https://github.com/acpica/acpica/commit/2802af72
Signed-off-by: Armin Wolf <W_Armin@gmx.de>
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
drivers/acpi/acpica/psargs.c

index 422c074ed2897b8c19429d9ff77c0a562c9131a3..7debfd5ce0d866d7ba5f0851dc5e1b031e777bac 100644 (file)
@@ -820,6 +820,10 @@ acpi_ps_get_next_arg(struct acpi_walk_state *walk_state,
                            acpi_ps_get_next_namepath(walk_state, parser_state,
                                                      arg,
                                                      ACPI_NOT_METHOD_CALL);
+                       if (ACPI_FAILURE(status)) {
+                               acpi_ps_free_op(arg);
+                               return_ACPI_STATUS(status);
+                       }
                } else {
                        /* Single complex argument, nothing returned */
 
@@ -854,6 +858,10 @@ acpi_ps_get_next_arg(struct acpi_walk_state *walk_state,
                            acpi_ps_get_next_namepath(walk_state, parser_state,
                                                      arg,
                                                      ACPI_POSSIBLE_METHOD_CALL);
+                       if (ACPI_FAILURE(status)) {
+                               acpi_ps_free_op(arg);
+                               return_ACPI_STATUS(status);
+                       }
 
                        if (arg->common.aml_opcode == AML_INT_METHODCALL_OP) {