summaryrefslogtreecommitdiff
path: root/drivers
diff options
context:
space:
mode:
authorXu Rao <raoxu@uniontech.com>2026-07-03 17:40:32 +0300
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>2026-07-08 13:38:24 +0200
commit49f6e3c3ef19f04f6657ed8dce550e36c763abb8 (patch)
tree5886b7481d0d3c3329de79ddd46b0068314bc800 /drivers
parent67e511d2989eb1c8c588b599ce2fcc6bb8e6f7ea (diff)
downloadlinux-next-49f6e3c3ef19f04f6657ed8dce550e36c763abb8.tar.gz
linux-next-49f6e3c3ef19f04f6657ed8dce550e36c763abb8.zip
xhci: sideband: fix ring sg table pages leak
xhci_ring_to_sgtable() allocates a temporary pages array and uses it to build the returned sg_table with sg_alloc_table_from_pages(). The error paths free the pages array, but the success path returns the sg_table without freeing it. This leaks the temporary array every time a sideband client gets an endpoint or event ring buffer. Free the pages array after sg_alloc_table_from_pages() succeeds. The returned sg_table has its own scatterlist entries and does not depend on the temporary array after construction. Fixes: de66754e9f80 ("xhci: sideband: add initial api to register a secondary interrupter entity") Cc: stable <stable@kernel.org> Signed-off-by: Xu Rao <raoxu@uniontech.com> Signed-off-by: Mathias Nyman <mathias.nyman@linux.intel.com> Link: https://patch.msgid.link/20260703144033.483286-2-mathias.nyman@linux.intel.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Diffstat (limited to 'drivers')
-rw-r--r--drivers/usb/host/xhci-sideband.c2
1 files changed, 2 insertions, 0 deletions
diff --git a/drivers/usb/host/xhci-sideband.c b/drivers/usb/host/xhci-sideband.c
index 23153e136d4b..a5deeee4d5dc 100644
--- a/drivers/usb/host/xhci-sideband.c
+++ b/drivers/usb/host/xhci-sideband.c
@@ -58,6 +58,8 @@ xhci_ring_to_sgtable(struct xhci_sideband *sb, struct xhci_ring *ring)
if (sg_alloc_table_from_pages(sgt, pages, n_pages, 0, sz, GFP_KERNEL))
goto err;
+ kvfree(pages);
+
/*
* Save first segment dma address to sg dma_address field for the sideband
* client to have access to the IOVA of the ring.