* [PATCH] PCI/IOV: Fix peer device reference leak in sriov_init()
@ 2026-09-17 13:27 Wentao Liang
2026-09-17 13:33 ` sashiko-bot
0 siblings, 1 reply; 2+ messages in thread
From: Wentao Liang @ 2026-09-17 13:27 UTC (permalink / raw)
To: aduyck; +Cc: bhelgaas, linux-kernel, linux-pci, Wentao Liang, stable
sriov_init() takes a reference to the SR-IOV physical function device
with pci_dev_get() and stores it in iov->dev. If the subsequent
compute_max_vf_buses() call fails, the fail_max_buses path frees iov
without dropping that reference, unlike sriov_release() which puts
iov->dev on the normal teardown path.
Drop the reference on the fail_max_buses path as well.
Fixes: ea9a8854161d ("PCI: Set SR-IOV NumVFs to zero after enumeration")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
---
drivers/pci/iov.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/pci/iov.c b/drivers/pci/iov.c
index 91ac4e37ecb9..f0687fe8514a 100644
--- a/drivers/pci/iov.c
+++ b/drivers/pci/iov.c
@@ -907,6 +907,8 @@ static int sriov_init(struct pci_dev *dev, int pos)
fail_max_buses:
dev->sriov = NULL;
dev->is_physfn = 0;
+ if (pdev)
+ pci_dev_put(pdev);
failed:
for (i = 0; i < PCI_SRIOV_NUM_BARS; i++) {
res = &dev->resource[pci_resource_num_from_vf_bar(i)];
--
2.34.1
^ permalink raw reply related [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-09-17 13:33 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-17 13:27 [PATCH] PCI/IOV: Fix peer device reference leak in sriov_init() Wentao Liang
2026-09-17 13:33 ` sashiko-bot
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox