From: Pavel Skripkin <paskripkin@gmail.com>
To: Dongliang Mu <mudongliangabcd@gmail.com>,
Mauro Carvalho Chehab <mchehab@kernel.org>,
linux-media@vger.kernel.org,
linux-kernel <linux-kernel@vger.kernel.org>
Cc: Greg KH <gregkh@linuxfoundation.org>,
Dan Carpenter <dan.carpenter@oracle.com>
Subject: Re: Need help in debugging "memory leak in em28xx_init_dev"
Date: Mon, 1 Nov 2021 10:50:07 +0300 [thread overview]
Message-ID: <55f04cb1-18ac-085b-3d35-7a01716fbcbe@gmail.com> (raw)
In-Reply-To: <CAD-N9QXsUcczurqq9LdaVjXFZMBSbStynwFJyu0UayDazGe=nw@mail.gmail.com>
[-- Attachment #1: Type: text/plain, Size: 1311 bytes --]
On 11/1/21 06:02, Dongliang Mu wrote:
> Hi all,
>
> My local syzkaller instance found one bug named "memory leak in
> em28xx_init_dev" in 5.14-rc5. Kernel configuration and PoC file are
> attached(I don't check if the latest kernel is vulnerable, but it
> should be). The trace from memleak is as follows:
>
> backtrace:
> [<ffffffff842cc66d>] kmalloc include/linux/slab.h:591 [inline]
> [<ffffffff842cc66d>] kzalloc include/linux/slab.h:721 [inline]
> [<ffffffff842cc66d>] em28xx_media_device_init
> drivers/media/usb/em28xx/em28xx-cards.c:3444 [inline]
> [<ffffffff842cc66d>] em28xx_init_dev.isra.0+0x366/0x9bf
> drivers/media/usb/em28xx/em28xx-cards.c:3624
> [<ffffffff842cd1bd>] em28xx_usb_probe.cold+0x4f7/0xf95
> drivers/media/usb/em28xx/em28xx-cards.c:3979
> [<ffffffff82bf0815>] usb_probe_interface+0x185/0x350
> drivers/usb/core/driver.c:396
>
Looks like missing clean up on error handling path.
->probe()
em28xx_init_dev()
em28xx_media_device_init() <- dev->media_dev allocated
*error somewhere in em28xx_init_dev()*
And then nothing unwinds em28xx_media_device_init() call, since
disconnect won't be called in case of failure in ->probe()
Just build tested, but, I guess, something like this should work.
With regards,
Pavel Skripkin
[-- Attachment #2: ph --]
[-- Type: text/plain, Size: 1219 bytes --]
diff --git a/drivers/media/usb/em28xx/em28xx-cards.c b/drivers/media/usb/em28xx/em28xx-cards.c
index c1e0dccb7408..f22e5ca2d1b3 100644
--- a/drivers/media/usb/em28xx/em28xx-cards.c
+++ b/drivers/media/usb/em28xx/em28xx-cards.c
@@ -3626,7 +3626,7 @@ static int em28xx_init_dev(struct em28xx *dev, struct usb_device *udev,
if (dev->is_audio_only) {
retval = em28xx_audio_setup(dev);
if (retval)
- return -ENODEV;
+ goto deinit_media;
em28xx_init_extension(dev);
return 0;
@@ -3645,7 +3645,7 @@ static int em28xx_init_dev(struct em28xx *dev, struct usb_device *udev,
dev_err(&dev->intf->dev,
"%s: em28xx_i2c_register bus 0 - error [%d]!\n",
__func__, retval);
- return retval;
+ goto deinit_media;
}
/* register i2c bus 1 */
@@ -3663,7 +3663,7 @@ static int em28xx_init_dev(struct em28xx *dev, struct usb_device *udev,
em28xx_i2c_unregister(dev, 0);
- return retval;
+ goto deinit_media;
}
}
@@ -3671,6 +3671,10 @@ static int em28xx_init_dev(struct em28xx *dev, struct usb_device *udev,
em28xx_card_setup(dev);
return 0;
+
+deinit_media:
+ em28xx_unregister_media_device(dev);
+ return retval;
}
static int em28xx_duplicate_dev(struct em28xx *dev)
next prev parent reply other threads:[~2021-11-01 7:50 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2021-11-01 3:02 Need help in debugging "memory leak in em28xx_init_dev" Dongliang Mu
2021-11-01 7:50 ` Pavel Skripkin [this message]
2021-11-01 8:55 ` Dongliang Mu
2021-11-01 9:19 ` Pavel Skripkin
2021-11-01 9:41 ` Dongliang Mu
2021-11-01 9:43 ` Pavel Skripkin
2021-11-01 9:58 ` Dongliang Mu
2021-11-01 12:17 ` Pavel Skripkin
2021-11-01 12:23 ` Dongliang Mu
2021-11-01 12:26 ` Pavel Skripkin
2021-11-01 12:31 ` Dongliang Mu
2021-11-01 14:30 ` Dan Carpenter
2021-11-01 14:33 ` Dongliang Mu
2021-11-01 15:05 ` Randy Dunlap
2021-11-01 18:33 ` Dan Carpenter
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=55f04cb1-18ac-085b-3d35-7a01716fbcbe@gmail.com \
--to=paskripkin@gmail.com \
--cc=dan.carpenter@oracle.com \
--cc=gregkh@linuxfoundation.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-media@vger.kernel.org \
--cc=mchehab@kernel.org \
--cc=mudongliangabcd@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.