accel/ethosu: fix job completion fence cleanup
Published Sep 16, 2026
No CVSS score
EPSS 0.20%
Description
ethosu_ioctl_submit_job() allocates done_fence before validating buffer handles. Errors after allocation call ethosu_job_err_cleanup(), which frees the job but leaks the uninitialized fence.
A scheduler dependency error also lets ethosu_job_run() return before dma_fence_init(). Normal cleanup then passes a zeroed refcount to dma_fence_put().
Release done_fence in the common cleanup path and use dma_fence_was_initialized() to distinguish initialized fences from raw allocations.
[robh: also fix goto]
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 6.19StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<6.19
- Version 7.2.5StatusunaffectedConstraints<=7.2.*
- Version 7.3-rc2StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
No CWE recorded.
References (2)
Change history (0)
No recorded changes yet.