From: Murad Masimov <m.masimov@mt-integration.ru>
To: Mark Fasheh <mark@fasheh.com>
Cc: Joel Becker <jlbec@evilplan.org>,
Joseph Qi <joseph.qi@linux.alibaba.com>, Jan Kara <jack@suse.cz>,
<ocfs2-devel@lists.linux.dev>, <linux-kernel@vger.kernel.org>,
<lvc-project@linuxtesting.org>,
Murad Masimov <m.masimov@mt-integration.ru>
Subject: [PATCH 1/2] ocfs2: Fix possible memory leak in ocfs2_finish_quota_recovery
Date: Wed, 2 Apr 2025 09:56:27 +0300 [thread overview]
Message-ID: <20250402065628.706359-2-m.masimov@mt-integration.ru> (raw)
In-Reply-To: <20250402065628.706359-1-m.masimov@mt-integration.ru>
If ocfs2_finish_quota_recovery() exits due to an error before passing all
rc_list elements to ocfs2_recover_local_quota_file() then it can lead to
a memory leak as rc_list may still contain elements that have to be freed.
Release all memory allocated by ocfs2_add_recovery_chunk() using
ocfs2_free_quota_recovery() instead of kfree().
Found by Linux Verification Center (linuxtesting.org) with Syzkaller.
Fixes: 2205363dce74 ("ocfs2: Implement quota recovery")
Signed-off-by: Murad Masimov <m.masimov@mt-integration.ru>
---
fs/ocfs2/quota_local.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/fs/ocfs2/quota_local.c b/fs/ocfs2/quota_local.c
index 2956d888c131..e60383d6ecc1 100644
--- a/fs/ocfs2/quota_local.c
+++ b/fs/ocfs2/quota_local.c
@@ -678,7 +678,7 @@ int ocfs2_finish_quota_recovery(struct ocfs2_super *osb,
}
out:
up_read(&sb->s_umount);
- kfree(rec);
+ ocfs2_free_quota_recovery(rec);
return status;
}
--
2.39.2
next prev parent reply other threads:[~2025-04-02 6:57 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-04-02 6:56 [PATCH 0/2] ocfs2: Fix issues in ocfs2_finish_quota_recovery Murad Masimov
2025-04-02 6:56 ` Murad Masimov [this message]
2025-04-02 12:36 ` [PATCH 1/2] ocfs2: Fix possible memory leak " Jan Kara
2025-04-03 0:56 ` Joseph Qi
2025-04-02 6:56 ` [PATCH 2/2] ocfs2: Fix deadlock " Murad Masimov
2025-04-03 1:28 ` Joseph Qi
2025-04-03 1:44 ` Heming Zhao
2025-04-03 11:33 ` Jan Kara
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20250402065628.706359-2-m.masimov@mt-integration.ru \
--to=m.masimov@mt-integration.ru \
--cc=jack@suse.cz \
--cc=jlbec@evilplan.org \
--cc=joseph.qi@linux.alibaba.com \
--cc=linux-kernel@vger.kernel.org \
--cc=lvc-project@linuxtesting.org \
--cc=mark@fasheh.com \
--cc=ocfs2-devel@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.