NVDIMM Device and Persistent Memory development
 help / color / mirror / Atom feed
* [PATCH] nvdimm/bus: Fix dev double put in nd_async_device_register()
@ 2026-09-17 12:28 Wentao Liang
  2026-09-17 12:44 ` sashiko-bot
  0 siblings, 1 reply; 2+ messages in thread
From: Wentao Liang @ 2026-09-17 12:28 UTC (permalink / raw)
  To: dave.jiang
  Cc: djbw, ira.weiny, linux-kernel, nvdimm, vishal.l.verma,
	Wentao Liang, stable

device_add() takes and drops its own reference on every return path, so
the async worker only owns the reference that __nd_device_register()
took with get_device(). The failure branch drops that same reference once
more before the unconditional put_device(), which underflows the refcount
and frees the device while it is still referenced by its creator, as
reported by KASAN for the parent pointer access in this function.

Drop the spurious put_device() from the failure branch.

Fixes: 4d88a97aa9e8c ("libnvdimm, nvdimm: dimm driver and base libnvdimm device-driver infrastructure")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
---
 drivers/nvdimm/bus.c | 4 +---
 1 file changed, 1 insertion(+), 3 deletions(-)

diff --git a/drivers/nvdimm/bus.c b/drivers/nvdimm/bus.c
index 45b7d756e39a..a1f33a03aba8 100644
--- a/drivers/nvdimm/bus.c
+++ b/drivers/nvdimm/bus.c
@@ -488,10 +488,8 @@ static void nd_async_device_register(void *d, async_cookie_t cookie)
 	struct device *dev = d;
 	struct device *parent = dev->parent;
 
-	if (device_add(dev) != 0) {
+	if (device_add(dev) != 0)
 		dev_err(dev, "%s: failed\n", __func__);
-		put_device(dev);
-	}
 	put_device(dev);
 	if (parent)
 		put_device(parent);
-- 
2.34.1


^ permalink raw reply related	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-09-17 12:44 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-17 12:28 [PATCH] nvdimm/bus: Fix dev double put in nd_async_device_register() Wentao Liang
2026-09-17 12:44 ` sashiko-bot

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox