]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked()
authorShuicheng Lin <shuicheng.lin@intel.com>
Wed, 8 Apr 2026 17:52:52 +0000 (17:52 +0000)
committerShuicheng Lin <shuicheng.lin@intel.com>
Tue, 14 Apr 2026 15:36:10 +0000 (08:36 -0700)
When type is ttm_bo_type_device and aligned_size != size, the function
returns an error without freeing a caller-provided bo, violating the
documented contract that bo is freed on failure.

Add xe_bo_free(bo) before returning the error.

Fixes: 4e03b584143e ("drm/xe/uapi: Reject bo creation of unaligned size")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-4.6
Reviewed-by: Matthew Brost <matthew.brost@intel.com>
Link: https://patch.msgid.link/20260408175255.3402838-2-shuicheng.lin@intel.com
Signed-off-by: Shuicheng Lin <shuicheng.lin@intel.com>
drivers/gpu/drm/xe/xe_bo.c

index daac53168dba093352d4519849e165b6098cb09d..c2f4f9090fb0e6dc496b7db6b105b141a53d16c5 100644 (file)
@@ -2329,8 +2329,10 @@ struct xe_bo *xe_bo_init_locked(struct xe_device *xe, struct xe_bo *bo,
                alignment = SZ_4K >> PAGE_SHIFT;
        }
 
-       if (type == ttm_bo_type_device && aligned_size != size)
+       if (type == ttm_bo_type_device && aligned_size != size) {
+               xe_bo_free(bo);
                return ERR_PTR(-EINVAL);
+       }
 
        if (!bo) {
                bo = xe_bo_alloc();