mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-08-30 11:03:07 -04:00
clocksource/drivers/nxp-pit: Fix IRQ leak on cpuhp_setup_state error path
When cpuhp_setup_state fails after pit_clockevent_per_cpu_init has
successfully called request_irq, the error handling jumps directly to
out_pit_clocksource_unregister without freeing the registered IRQ.
This leaks the IRQ line and, since kfree(pit) follows, leaves a
dangling pointer registered as the interrupt handler's dev_id,
potentially leading to a use-after-free if the IRQ fires afterwards.
Fix it by calling pit_clockevent_per_cpu_exit to properly release the
IRQ before falling through to the existing cleanup chain.
Suggested-by: Greg KH <gregkh@linuxfoundation.org>
Fixes: bee33f22d7 ("clocksource/drivers/nxp-pit: Add NXP Automotive s32g2 / s32g3 support")
Cc: stable@vger.kernel.org
Signed-off-by: WenTao Liang <vulab@iscas.ac.cn>
Signed-off-by: Daniel Lezcano <daniel.lezcano@kernel.org>
Link: https://patch.msgid.link/20260628130700.45680-1-vulab@iscas.ac.cn
This commit is contained in:
committed by
Daniel Lezcano
parent
d218083282
commit
05520e035f
@@ -328,8 +328,10 @@ static int pit_timer_init(struct device_node *np)
|
||||
if (pit_instances == max_pit_instances) {
|
||||
ret = cpuhp_setup_state(CPUHP_AP_ONLINE_DYN, "PIT timer:starting",
|
||||
pit_clockevent_starting_cpu, NULL);
|
||||
if (ret < 0)
|
||||
if (ret < 0) {
|
||||
pit_clockevent_per_cpu_exit(pit, pit_instances);
|
||||
goto out_pit_clocksource_unregister;
|
||||
}
|
||||
}
|
||||
|
||||
return 0;
|
||||
|
||||
Reference in New Issue
Block a user