Patchwork [2/2] UBIFS: fix memory leak on error path

login
register
mail settings
Submitter Artem Bityutskiy
Date May 18, 2012, 11:32 a.m.
Message ID <1337340757-26127-2-git-send-email-dedekind1@gmail.com>
Download mbox | patch
Permalink /patch/160096/
State Accepted
Commit 56b04e3e8b5cbf71c23a739f34f9a9437afa41fb
Headers show

Comments

Artem Bityutskiy - May 18, 2012, 11:32 a.m.
From: Sidney Amani <seed95@gmail.com>

UBIFS leaks memory on error path in 'mount_ubifs()'. In case of failure in
'ubifs_fixup_free_space()', it does not call 'ubifs_lpt_free()' whereas LPT
data structures can potentially be allocated. The amount of memory leaked can
be quite high -- see 'ubifs_lpt_init()'.

The bug was introduced when moving the LPT initialisation earlier in the
mount process (commit '781c5717a95a74b294beb38b8276943b0f8b5bb4').

Signed-off-by: Sidney Amani <seed95@gmail.com>
Signed-off-by: Artem Bityutskiy <artem.bityutskiy@linux.intel.com>
---
 fs/ubifs/super.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

Patch

diff --git a/fs/ubifs/super.c b/fs/ubifs/super.c
index 5b30c4d..675b781 100644
--- a/fs/ubifs/super.c
+++ b/fs/ubifs/super.c
@@ -1301,7 +1301,7 @@  static int mount_ubifs(struct ubifs_info *c)
 	if (!c->ro_mount && c->space_fixup) {
 		err = ubifs_fixup_free_space(c);
 		if (err)
-			goto out_master;
+			goto out_lpt;
 	}
 
 	if (!c->ro_mount) {