[PATCH] statd: fix memory leak in sm_mon_1_svc() when existing host re-monitors

xuchenchen <[email protected]> Tue, 28 Jul 2026 16:33:47 +0800
Newsgroups org.kernel.vger.linux-nfs
Message-ID <[email protected]>
From: xuchenchen <[email protected]>

When an already-monitored host sends a new SM_MON request with a
different priv cookie, the code sets existing=1 and reuses the
existing notify_list entry. However, clnt->dns_name is overwritten
with the newly allocated dnsname without freeing the old value,
causing a memory leak.

Since statd is a long-running daemon, repeated SM_MON requests with
changing cookies will accumulate leaked strings.

Fix by freeing the old dns_name before overwriting it.

Signed-off-by: xuchenchen <[email protected]>
---
 utils/statd/monitor.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/utils/statd/monitor.c b/utils/statd/monitor.c
index c76589ca..76ef16f1 100644
--- a/utils/statd/monitor.c
+++ b/utils/statd/monitor.c
@@ -187,6 +187,8 @@ sm_mon_1_svc(struct mon *argp, struct svc_req *rqstp)
 	NL_MY_VERS(clnt) = id->my_vers;
 	NL_MY_PROC(clnt) = id->my_proc;
 	memcpy(NL_PRIV(clnt), argp->priv, SM_PRIV_SIZE);
+	if (existing)
+		free(clnt->dns_name);
 	clnt->dns_name = dnsname;
 
 	/*
-- 
2.47.3