fs_enet_probe() allocates the platform information structure with
kzalloc_obj() and stores it in fep->fpi.

The probe failure paths release this allocation with kfree(). However,
after a successful probe, fs_enet_remove() tears down the network
device without freeing fep->fpi, leaving the platform information
structure allocated after driver removal.

Free fep->fpi before releasing the network device.

This issue was found by manual code inspection.

Fixes: 976de6a8c304 ("fs_enet: Be an of_platform device when 
CONFIG_PPC_CPM_NEW_BINDING is set.")
Cc: [email protected]
Signed-off-by: Guangshuo Li <[email protected]>
---
 drivers/net/ethernet/freescale/fs_enet/fs_enet-main.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/net/ethernet/freescale/fs_enet/fs_enet-main.c 
b/drivers/net/ethernet/freescale/fs_enet/fs_enet-main.c
index d3c772ed5fc9..071e3f3de78c 100644
--- a/drivers/net/ethernet/freescale/fs_enet/fs_enet-main.c
+++ b/drivers/net/ethernet/freescale/fs_enet/fs_enet-main.c
@@ -1007,6 +1007,7 @@ static void fs_enet_remove(struct platform_device *ofdev)
        fep->ops->cleanup_data(ndev);
        dev_set_drvdata(fep->dev, NULL);
        phylink_destroy(fep->phylink);
+       kfree(fep->fpi);
        free_netdev(ndev);
 }
 
-- 
2.43.0


Reply via email to