On Wed Apr 15 23:45:37 2026 +0800, Guangshuo Li wrote:
> When platform_device_register() fails in vimc_init(), the embedded
> struct device in vimc_pdev has already been initialized by
> device_initialize(), but the failure path returns the error without
> dropping the device reference for the current platform device:
> 
>   vimc_init()
>     -> platform_device_register(&vimc_pdev)
>        -> device_initialize(&vimc_pdev.dev)
>        -> setup_pdev_dma_masks(&vimc_pdev)
>        -> platform_device_add(&vimc_pdev)
> 
> This leads to a reference leak when platform_device_register() fails.
> Fix this by calling platform_device_put() before returning the error.
> 
> The issue was identified by a static analysis tool I developed and
> confirmed by manual review.
> 
> Fixes: 4babf057c143f ("media: vimc: allocate vimc_device dynamically")
> Cc: [email protected]
> Signed-off-by: Guangshuo Li <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>

Patch committed.

Thanks,
Hans Verkuil

 drivers/media/test-drivers/vimc/vimc-core.c | 1 +
 1 file changed, 1 insertion(+)

---

diff --git a/drivers/media/test-drivers/vimc/vimc-core.c 
b/drivers/media/test-drivers/vimc/vimc-core.c
index 15167e127461..fee0c7a09c4f 100644
--- a/drivers/media/test-drivers/vimc/vimc-core.c
+++ b/drivers/media/test-drivers/vimc/vimc-core.c
@@ -421,6 +421,7 @@ static int __init vimc_init(void)
        if (ret) {
                dev_err(&vimc_pdev.dev,
                        "platform device registration failed (err=%d)\n", ret);
+               platform_device_put(&vimc_pdev);
                return ret;
        }
 
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to