[PATCH] target: iscsi: cxgbit: fix cnp kref leak in __cxgbit_free_cdev_np()
Wentao Liang <[email protected]> Wed, 27 May 2026 10:38:23 +0000
| Newsgroups | org.kernel.vger.target-devel,org.kernel.vger.linux-kernel,org.kernel.vger.linux-scsi,org.kernel.vger.stable |
|---|---|
| Message-ID | <[email protected]> |
__cxgbit_free_cdev_np() calls cxgbit_get_cnp() which takes a kref reference on the cnp structure. This reference is only released on the immediate error path after cxgbit_get_cnp(). On the timeout path and the normal completion path that successfully processes the NP, the reference is never released via cxgbit_put_cnp(), leaking the kref. Add cxgbit_put_cnp(cnp) on the timeout and success paths to properly release the kref reference. Cc: [email protected] Fixes: 9730ffcb8957 ("cxgbit: add files for cxgbit.ko") Signed-off-by: Wentao Liang <[email protected]> --- drivers/target/iscsi/cxgbit/cxgbit_cm.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/drivers/target/iscsi/cxgbit/cxgbit_cm.c b/drivers/target/iscsi/cxgbit/cxgbit_cm.c index 146705845fa3..11149d73c844 100644 --- a/drivers/target/iscsi/cxgbit/cxgbit_cm.c +++ b/drivers/target/iscsi/cxgbit/cxgbit_cm.c @@ -545,6 +545,7 @@ __cxgbit_free_cdev_np(struct cxgbit_device *cdev, struct cxgbit_np *cnp) ret = cxgbit_wait_for_reply(cdev, &cnp->com.wr_wait, 0, 10, __func__); if (ret == -ETIMEDOUT) + cxgbit_put_cnp(cnp); return ret; if (ipv6 && cnp->com.cdev) { @@ -558,6 +559,7 @@ __cxgbit_free_cdev_np(struct cxgbit_device *cdev, struct cxgbit_np *cnp) cxgb4_free_stid(cdev->lldi.tids, stid, cnp->com.local_addr.ss_family); + cxgbit_put_cnp(cnp); return 0; } -- 2.34.1