]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
USB: gadget: f_hid: Fix memory leak in hidg_bind error path
authorYuhao Jiang <danisjiang@gmail.com>
Mon, 23 Jun 2025 09:48:44 +0000 (17:48 +0800)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Mon, 7 Jul 2025 09:03:33 +0000 (11:03 +0200)
In hidg_bind(), if alloc_workqueue() fails after usb_assign_descriptors()
has successfully allocated the USB descriptors, the current error handling
does not call usb_free_all_descriptors() to free the allocated descriptors,
resulting in a memory leak.

Restructure the error handling by adding proper cleanup labels:
- fail_free_all: cleans up workqueue and descriptors
- fail_free_descs: cleans up descriptors only
- fail: original cleanup for earlier failures

This ensures that allocated resources are properly freed in reverse order
of their allocation, preventing the memory leak when alloc_workqueue() fails.

Fixes: a139c98f760ef ("USB: gadget: f_hid: Add GET_REPORT via userspace IOCTL")
Cc: stable@vger.kernel.org
Signed-off-by: Yuhao Jiang <danisjiang@gmail.com>
Link: https://lore.kernel.org/r/20250623094844.244977-1-danisjiang@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
drivers/usb/gadget/function/f_hid.c

index 97a62b9264150f4948a6f2dd4341d04299a3057b..8e1d1e8840503efe0e727ad30c1158b95789a0fd 100644 (file)
@@ -1278,18 +1278,19 @@ static int hidg_bind(struct usb_configuration *c, struct usb_function *f)
 
        if (!hidg->workqueue) {
                status = -ENOMEM;
-               goto fail;
+               goto fail_free_descs;
        }
 
        /* create char device */
        cdev_init(&hidg->cdev, &f_hidg_fops);
        status = cdev_device_add(&hidg->cdev, &hidg->dev);
        if (status)
-               goto fail_free_descs;
+               goto fail_free_all;
 
        return 0;
-fail_free_descs:
+fail_free_all:
        destroy_workqueue(hidg->workqueue);
+fail_free_descs:
        usb_free_all_descriptors(f);
 fail:
        ERROR(f->config->cdev, "hidg_bind FAILED\n");