Re: [PATCH] scsi: elx: efct: fix refcount leak in efct_hw_io_abort()
"Martin K. Petersen" <[email protected]> Sun, 12 Jul 2026 22:32:38 -0400
| Newsgroups | org.kernel.vger.target-devel,org.kernel.vger.linux-kernel,org.kernel.vger.linux-scsi,org.kernel.vger.stable |
|---|---|
| Message-ID | <[email protected]> |
On Thu, 11 Jun 2026 13:30:37 +0800, WenTao Liang wrote:
> When efct_hw_reqtag_alloc() fails in efct_hw_io_abort(), the error
> path returns -ENOSPC without releasing the reference obtained via
> kref_get_unless_zero() earlier in the function. All other error
> paths correctly drop the reference. This causes a permanent
> reference leak on the io_to_abort object.
>
> Additionally, the abort_in_progress flag is left set to true on
> this path, which means future abort attempts for the same I/O will
> immediately return -EINPROGRESS even though the abort was never
> submitted, effectively blocking recovery.
>
> [...]
Applied to 7.2/scsi-fixes, thanks!
[1/1] scsi: elx: efct: fix refcount leak in efct_hw_io_abort()
https://git.kernel.org/mkp/scsi/c/2c007acf7b31
--
Martin K. Petersen