gpiolib: fix memory leak in gpiochip_setup_dev()
Published Oct 21, 2024
7.1
HIGHCVSS 3.1
EPSS 0.24%
Description
Here is a backtrace report about memory leak detected in gpiochip_setup_dev():
unreferenced object 0xffff88810b406400 (size 512): comm "python3", pid 1682, jiffies 4295346908 (age 24.090s) backtrace: kmalloc_trace device_add device_private_init at drivers/base/core.c:3361 (inlined by) device_add at drivers/base/core.c:3411 cdev_device_add gpiolib_cdev_register gpiochip_setup_dev gpiochip_add_data_with_key
gcdev_register() & gcdev_unregister() would call device_add() & device_del() (no matter CONFIG_GPIO_CDEV is enabled or not) to register/unregister device.
However, if device_add() succeeds, some resource (like struct device_private allocated by device_private_init()) is not released by device_del().
Therefore, after device_add() succeeds by gcdev_register(), it needs to call put_device() to release resource in the error handle path.
Here we move forward the register of release function, and let it release every piece of resource by put_device() instead of kfree().
While at it, fix another subtle issue, i.e. when gc->ngpio is equal to 0, we still call kcalloc() and, in case of further error, kfree() on the ZERO_PTR pointer, which is not NULL. It's not a bug per se, but rather waste of the resources and potentially wrong expectation about contents of the gdev->descs variable.
Affected products
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- 4.6
Unaffected
- ≥ 0, < 4.6
- ≥ 5.15.83, ≤ 5.15.*
- ≥ 6.0.13, ≤ 6.0.*
- 6.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
- ≥ 4.6 · < 5.15.83
- ≥ 5.16 · < 6.0.13
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
No data.
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Will not fix
Red Hat Enterprise Linux 8
kernel-rt
Will not fix
Red Hat Enterprise Linux 9
kernel
Affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Will not fix | n/a |
| Red Hat Enterprise Linux 9 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (9)
- https://access.redhat.com/security/cve/CVE-2022-48975 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2320704 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-53854 Advisory
- https://git.kernel.org/stable/c/371363716398ed718e389bea8c5e9843a79dde4e Patch
- https://git.kernel.org/stable/c/6daaa84b621485fe28c401be18debf92ae8ef04a Patch
- https://git.kernel.org/stable/c/ec851b23084b3a0af8bf0f5e51d33a8d678bdc49 Patch
- https://lore.kernel.org/linux-cve-announce/2024102145-CVE-2022-48975-d7f9@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-48975
- https://www.cve.org/CVERecord?id=CVE-2022-48975
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data