Commit 35335330 authored by Wei Li's avatar Wei Li Committed by Linus Walleij
Browse files

pinctrl: single: fix refcount leak in pcs_add_gpio_func()



of_parse_phandle_with_args() returns a device_node pointer with refcount
incremented in gpiospec.np. The loop iterates through all phandles but
never releases the reference, causing a refcount leak on each iteration.

Add of_node_put() calls to release the reference after extracting the
needed arguments and on the error path when devm_kzalloc() fails.

This bug was detected by our static analysis tool and verified by my
code review.

Fixes: a1a277eb ("pinctrl: single: create new gpio function range")
Signed-off-by: default avatarWei Li <unsw.weili@gmail.com>
Signed-off-by: default avatarLinus Walleij <linusw@kernel.org>
parent e56aa18e
Loading
Loading
Loading
Loading
+2 −0
Original line number Diff line number Diff line
@@ -1359,6 +1359,7 @@ static int pcs_add_gpio_func(struct device_node *node, struct pcs_device *pcs)
		}
		range = devm_kzalloc(pcs->dev, sizeof(*range), GFP_KERNEL);
		if (!range) {
			of_node_put(gpiospec.np);
			ret = -ENOMEM;
			break;
		}
@@ -1368,6 +1369,7 @@ static int pcs_add_gpio_func(struct device_node *node, struct pcs_device *pcs)
		mutex_lock(&pcs->mutex);
		list_add_tail(&range->node, &pcs->gpiofuncs);
		mutex_unlock(&pcs->mutex);
		of_node_put(gpiospec.np);
	}
	return ret;
}