2022-11-23 04:03:59

by Xiu Jianfeng

[permalink] [raw]
Subject: [PATCH] clk: rockchip: Fix memory leak in rockchip_clk_register_pll()

If clk_register() fails, @pll->rate_table may have allocated memory by
kmemdup(), so it needs to be freed, otherwise will cause memory leak
issue, this patch fixes it.

Fixes: 90c590254051 ("clk: rockchip: add clock type for pll clocks and pll used on rk3066")
Signed-off-by: Xiu Jianfeng <[email protected]>
---
drivers/clk/rockchip/clk-pll.c | 1 +
1 file changed, 1 insertion(+)

diff --git a/drivers/clk/rockchip/clk-pll.c b/drivers/clk/rockchip/clk-pll.c
index 4b9840994295..dc4ce280d125 100644
--- a/drivers/clk/rockchip/clk-pll.c
+++ b/drivers/clk/rockchip/clk-pll.c
@@ -1200,6 +1200,7 @@ struct clk *rockchip_clk_register_pll(struct rockchip_clk_provider *ctx,
clk_unregister(mux_clk);
mux_clk = pll_clk;
err_mux:
+ kfree(pll->rate_table);
kfree(pll);
return mux_clk;
}
--
2.17.1


2022-11-23 09:55:30

by Heiko Stuebner

[permalink] [raw]
Subject: Re: [PATCH] clk: rockchip: Fix memory leak in rockchip_clk_register_pll()

Hi,

Am Mittwoch, 23. November 2022, 04:22:37 CET schrieb Xiu Jianfeng:
> If clk_register() fails, @pll->rate_table may have allocated memory by
> kmemdup(), so it needs to be freed, otherwise will cause memory leak
> issue, this patch fixes it.
>
> Fixes: 90c590254051 ("clk: rockchip: add clock type for pll clocks and pll used on rk3066")
> Signed-off-by: Xiu Jianfeng <[email protected]>
> ---
> drivers/clk/rockchip/clk-pll.c | 1 +
> 1 file changed, 1 insertion(+)
>
> diff --git a/drivers/clk/rockchip/clk-pll.c b/drivers/clk/rockchip/clk-pll.c
> index 4b9840994295..dc4ce280d125 100644
> --- a/drivers/clk/rockchip/clk-pll.c
> +++ b/drivers/clk/rockchip/clk-pll.c
> @@ -1200,6 +1200,7 @@ struct clk *rockchip_clk_register_pll(struct rockchip_clk_provider *ctx,
> clk_unregister(mux_clk);
> mux_clk = pll_clk;
> err_mux:
> + kfree(pll->rate_table);

I think this free needs to go up to the err_pll block.

In the code it is
- clk_register(pll_mux->hw) -> err_mux
- kmemdup
- clk_register(pll->hw) -> err_pll

so the kfree for the rate-table should probably
be at
err_pll:
kfree(rate_table)
clk_unregister(mux_clk);
...


Heiko

> kfree(pll);
> return mux_clk;
> }
>




2022-11-23 10:21:56

by Xiu Jianfeng

[permalink] [raw]
Subject: Re: [PATCH] clk: rockchip: Fix memory leak in rockchip_clk_register_pll()

Hi,

?? 2022/11/23 17:01, Heiko Stuebner ะด??:
> Hi,
>
> Am Mittwoch, 23. November 2022, 04:22:37 CET schrieb Xiu Jianfeng:
>> If clk_register() fails, @pll->rate_table may have allocated memory by
>> kmemdup(), so it needs to be freed, otherwise will cause memory leak
>> issue, this patch fixes it.
>>
>> Fixes: 90c590254051 ("clk: rockchip: add clock type for pll clocks and pll used on rk3066")
>> Signed-off-by: Xiu Jianfeng <[email protected]>
>> ---
>> drivers/clk/rockchip/clk-pll.c | 1 +
>> 1 file changed, 1 insertion(+)
>>
>> diff --git a/drivers/clk/rockchip/clk-pll.c b/drivers/clk/rockchip/clk-pll.c
>> index 4b9840994295..dc4ce280d125 100644
>> --- a/drivers/clk/rockchip/clk-pll.c
>> +++ b/drivers/clk/rockchip/clk-pll.c
>> @@ -1200,6 +1200,7 @@ struct clk *rockchip_clk_register_pll(struct rockchip_clk_provider *ctx,
>> clk_unregister(mux_clk);
>> mux_clk = pll_clk;
>> err_mux:
>> + kfree(pll->rate_table);
>
> I think this free needs to go up to the err_pll block.
>
> In the code it is
> - clk_register(pll_mux->hw) -> err_mux
> - kmemdup
> - clk_register(pll->hw) -> err_pll
>
> so the kfree for the rate-table should probably
> be at
> err_pll:
> kfree(rate_table)

Thanks for you review, I think here should be kfree(pll->rate_table)
instead of kfree(rate_table), because @rate_table is the intput param
while pll->rate_table is the new allocated memory.

v2 already sent.

> clk_unregister(mux_clk);
> ...
>
>
> Heiko
>
>> kfree(pll);
>> return mux_clk;
>> }
>>
>
>
>
>
>
> .
>