On 14-07-2026 22:30, Matthew Brost wrote:
If kvmalloc_array() fails in drm_gpusvm_range_evict(), the MM
reference acquired earlier is not released, resulting in a reference
leak.

Fix this by dropping the MM reference on the kvmalloc_array()
failure path.

Fixes: 99624bdff867 ("drm/gpusvm: Add support for GPU Shared Virtual Memory")
Cc: [email protected]
Signed-off-by: Matthew Brost <[email protected]>
---
  drivers/gpu/drm/drm_gpusvm.c | 4 +++-
  1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/drm_gpusvm.c b/drivers/gpu/drm/drm_gpusvm.c
index f45bf1d59a06..ac1f135abe68 100644
--- a/drivers/gpu/drm/drm_gpusvm.c
+++ b/drivers/gpu/drm/drm_gpusvm.c
@@ -1778,8 +1778,10 @@ int drm_gpusvm_range_evict(struct drm_gpusvm *gpusvm,
                return -EFAULT;
pfns = kvmalloc_array(npages, sizeof(*pfns), GFP_KERNEL);
-       if (!pfns)
+       if (!pfns) {
+               mmput(mm);
                return -ENOMEM;
+       }

LGTM

Reviewed-by: Himal Prasad Ghimiray <[email protected]>

hmm_range.hmm_pfns = pfns;
        while (!time_after(jiffies, timeout)) {

Reply via email to