public inbox for linux-serial@vger.kernel.org
 help / color / mirror / Atom feed
* [PATCH] drivers/tty/tty_io.c: fix a potential memleak at do_tty_write()
@ 2012-06-18 12:23 Jeff Liu
  2012-06-18 15:26 ` Greg KH
  2012-06-18 16:04 ` Alan Cox
  0 siblings, 2 replies; 5+ messages in thread
From: Jeff Liu @ 2012-06-18 12:23 UTC (permalink / raw)
  To: linux-serial

Hello,

Looks there is a potential memory leak at drivers/tty/tty_io.c: do_tty_write().
It did allocate a buf_chunk if tty->write_cnt < chunk, however, buf_chunk was not
freed after the writing is done.  Below tiny patch could fix it.

Thanks,
-Jeff


diff --git a/drivers/tty/tty_io.c b/drivers/tty/tty_io.c
index b425c79..f09e73e 100644
--- a/drivers/tty/tty_io.c
+++ b/drivers/tty/tty_io.c
@@ -1011,6 +1011,7 @@ static inline ssize_t do_tty_write(
 	size_t count)
 {
 	ssize_t ret, written = 0;
+	unsigned char *buf_chunk = NULL;
 	unsigned int chunk;
 
 	ret = tty_write_lock(tty, file->f_flags & O_NDELAY);
@@ -1041,8 +1042,6 @@ static inline ssize_t do_tty_write(
 
 	/* write_buf/write_cnt is protected by the atomic_write_lock mutex */
 	if (tty->write_cnt < chunk) {
-		unsigned char *buf_chunk;
-
 		if (chunk < 1024)
 			chunk = 1024;
 
@@ -1082,6 +1081,9 @@ static inline ssize_t do_tty_write(
 		inode->i_mtime = current_fs_time(inode->i_sb);
 		ret = written;
 	}
+
+	if (buf_chunk)
+		kfree(buf_chunk);
 out:
 	tty_write_unlock(tty);
 	return ret;

^ permalink raw reply related	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2012-06-19  3:45 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2012-06-18 12:23 [PATCH] drivers/tty/tty_io.c: fix a potential memleak at do_tty_write() Jeff Liu
2012-06-18 15:26 ` Greg KH
2012-06-18 16:04 ` Alan Cox
2012-06-18 18:00   ` Paul Fulghum
2012-06-19  3:44     ` Jeff Liu

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox