]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
of: fix reference count leak in of_alias_scan()
authorWeigang He <geoffreyhe2@gmail.com>
Sat, 17 Jan 2026 09:12:38 +0000 (09:12 +0000)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Fri, 30 Jan 2026 09:27:38 +0000 (10:27 +0100)
commit 81122fba08fa3ccafab6ed272a5c6f2203923a7e upstream.

of_find_node_by_path() returns a device_node with its refcount
incremented. When kstrtoint() fails or dt_alloc() fails, the function
continues to the next iteration without calling of_node_put(), causing
a reference count leak.

Add of_node_put(np) before continue on both error paths to properly
release the device_node reference.

Fixes: 611cad720148 ("dt: add of_alias_scan and of_alias_get_id")
Cc: stable@vger.kernel.org
Signed-off-by: Weigang He <geoffreyhe2@gmail.com>
Link: https://patch.msgid.link/20260117091238.481243-1-geoffreyhe2@gmail.com
Signed-off-by: Rob Herring (Arm) <robh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
drivers/of/base.c

index ccadc22f18c0ecac95c5dcdfd7915c88757ec1be..d10248a5c0a5ce5404ada8b734e3b832f012de91 100644 (file)
@@ -1788,13 +1788,17 @@ void of_alias_scan(void * (*dt_alloc)(u64 size, u64 align))
                        end--;
                len = end - start;
 
-               if (kstrtoint(end, 10, &id) < 0)
+               if (kstrtoint(end, 10, &id) < 0) {
+                       of_node_put(np);
                        continue;
+               }
 
                /* Allocate an alias_prop with enough space for the stem */
                ap = dt_alloc(sizeof(*ap) + len + 1, __alignof__(*ap));
-               if (!ap)
+               if (!ap) {
+                       of_node_put(np);
                        continue;
+               }
                memset(ap, 0, sizeof(*ap) + len + 1);
                ap->alias = start;
                of_alias_add(ap, np, id, start, len);