From d053d56f5030c8e75ed7c3ec1a2abf553c8afca7 Mon Sep 17 00:00:00 2001 From: Aditya Bavanari Date: Wed, 27 May 2020 13:00:33 +0530 Subject: [PATCH] dsp: Fix a memory leak issue when nvmem read returns invalid length When nvmem cell read returns invalid length the allocated buffer is not freed. Free the buffer in this scenario to fix memory leak issue. Change-Id: I2e0010c1cfb2ea03cb4f25abf55e94ce4f0c5fcf Signed-off-by: Aditya Bavanari --- dsp/adsp-loader.c | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/dsp/adsp-loader.c b/dsp/adsp-loader.c index c8e1270b020a..e99d6a3c7265 100644 --- a/dsp/adsp-loader.c +++ b/dsp/adsp-loader.c @@ -388,10 +388,16 @@ static int adsp_loader_probe(struct platform_device *pdev) } buf = nvmem_cell_read(cell, &len); nvmem_cell_put(cell); - if (IS_ERR_OR_NULL(buf) || len <= 0 || len > sizeof(u32)) { + if (IS_ERR_OR_NULL(buf)) { dev_dbg(&pdev->dev, "%s: FAILED to read nvmem cell \n", __func__); goto wqueue; } + if (len <= 0 || len > sizeof(u32)) { + dev_dbg(&pdev->dev, "%s: nvmem cell length out of range: %d\n", + __func__, len); + kfree(buf); + goto wqueue; + } memcpy(&adsp_var_idx, buf, len); kfree(buf);