2003-03-13 20:10:58

by Oleg Drokin

[permalink] [raw]
Subject: Memleak in Internet PhoneJACK driver

Hello!

There is unfree memory on error return path in ixj_build_filter_cadence().
Trivial patch that applies to both 2.4 and 2.5 is below.
Found with help of smatch + enhanced ufree patch.

Bye,
Oleg

===== drivers/telephony/ixj.c 1.16 vs edited =====
--- 1.16/drivers/telephony/ixj.c Fri Aug 23 04:23:39 2002
+++ edited/drivers/telephony/ixj.c Thu Mar 13 23:15:51 2003
@@ -6001,12 +6001,14 @@
if(ixjdebug & 0x0001) {
printk(KERN_INFO "Could not copy cadence to kernel\n");
}
+ kfree(lcp);
return -EFAULT;
}
if (lcp->filter > 5) {
if(ixjdebug & 0x0001) {
printk(KERN_INFO "Cadence out of range\n");
}
+ kfree(lcp);
return -1;
}
j->cadence_f[lcp->filter].state = 0;