fs/sysfs/file.c | 2 ++ 1 file changed, 2 insertions(+)
The sysfs_break_active_protection() routine has an obvious reference
leak in its error path. If the call to kernfs_find_and_get() fails then
kn will be NULL, so the companion sysfs_unbreak_active_protection()
routine won't get called (and would only cause an access violation by
trying to dereference kn->parent if it was called). As a result, the
reference to kobj acquired at the start of the function will never be
released.
Fix the leak by adding an explicit kobject_put() call when kn is NULL.
Signed-off-by: Alan Stern <stern@rowland.harvard.edu>
Fixes: 2afc9166f79b ("scsi: sysfs: Introduce sysfs_{un,}break_active_protection()")
Cc: Bart Van Assche <bvanassche@acm.org>
Cc: <stable@vger.kernel.org>
---
fs/sysfs/file.c | 2 ++
1 file changed, 2 insertions(+)
Index: usb-devel/fs/sysfs/file.c
===================================================================
--- usb-devel.orig/fs/sysfs/file.c
+++ usb-devel/fs/sysfs/file.c
@@ -463,6 +463,8 @@ struct kernfs_node *sysfs_break_active_p
kn = kernfs_find_and_get(kobj->sd, attr->name);
if (kn)
kernfs_break_active_protection(kn);
+ else
+ kobject_put(kobj);
return kn;
}
EXPORT_SYMBOL_GPL(sysfs_break_active_protection);
On 3/13/24 14:43, Alan Stern wrote: > The sysfs_break_active_protection() routine has an obvious reference > leak in its error path. If the call to kernfs_find_and_get() fails then > kn will be NULL, so the companion sysfs_unbreak_active_protection() > routine won't get called (and would only cause an access violation by > trying to dereference kn->parent if it was called). As a result, the > reference to kobj acquired at the start of the function will never be > released. > > Fix the leak by adding an explicit kobject_put() call when kn is NULL. Reviewed-by: Bart Van Assche <bvanassche@acm.org>
On Wed, Mar 13, 2024 at 05:43:41PM -0400, Alan Stern wrote:
> The sysfs_break_active_protection() routine has an obvious reference
> leak in its error path. If the call to kernfs_find_and_get() fails then
> kn will be NULL, so the companion sysfs_unbreak_active_protection()
> routine won't get called (and would only cause an access violation by
> trying to dereference kn->parent if it was called). As a result, the
> reference to kobj acquired at the start of the function will never be
> released.
>
> Fix the leak by adding an explicit kobject_put() call when kn is NULL.
>
> Signed-off-by: Alan Stern <stern@rowland.harvard.edu>
> Fixes: 2afc9166f79b ("scsi: sysfs: Introduce sysfs_{un,}break_active_protection()")
> Cc: Bart Van Assche <bvanassche@acm.org>
> Cc: <stable@vger.kernel.org>
Acked-by: Tejun Heo <tj@kernel.org>
Thanks.
--
tejun
© 2016 - 2026 Red Hat, Inc.