From f510918743ec661825061b1e816abac1d00e5ab6 Mon Sep 17 00:00:00 2001 From: lixiang Date: Thu, 15 Jul 2021 17:13:11 +0800 Subject: [PATCH] soc: qcom: hab: Fix potential memory leak when receiving msg Fix potential memory leak situation when receiving a message of type HAB_PAYLOAD_TYPE_EXPORT_ACK. Add kfree() to free ack_recvd. Change-Id: Iaa5cb10af694b20647f2f04f3c030bfa2ba59a3d Signed-off-by: lixiang --- drivers/soc/qcom/hab/hab_msg.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/drivers/soc/qcom/hab/hab_msg.c b/drivers/soc/qcom/hab/hab_msg.c index 3a121f84afcd..00cc75a5a407 100644 --- a/drivers/soc/qcom/hab/hab_msg.c +++ b/drivers/soc/qcom/hab/hab_msg.c @@ -163,13 +163,16 @@ static int hab_receive_create_export_ack(struct physical_channel *pchan, if (sizebytes > sizeof(ack_recvd->ack)) { pr_err("pchan %s read size too large %zd %zd\n", pchan->name, sizebytes, sizeof(ack_recvd->ack)); + kfree(ack_recvd); return -EINVAL; } if (physical_channel_read(pchan, &ack_recvd->ack, - sizebytes) != sizebytes) + sizebytes) != sizebytes) { + kfree(ack_recvd); return -EIO; + } hab_spin_lock(&ctx->expq_lock, irqs_disabled); list_add_tail(&ack_recvd->node, &ctx->exp_rxq);