Re: [PATCH bpf-next] selftests/bpf: Fix memory leak in msg_alloc_iov

From: John Fastabend

Date: Tue Jul 07 2026 - 10:26:26 EST


On Tue, Jul 07, 2026 at 04:14:34PM +0800, Feng Yang wrote:
From: Feng Yang <yangfeng@xxxxxxxxxx>

In the msg_alloc_iov function, the iov pointer is only assigned to
msg->msg_iov after all memory allocations complete successfully.
Therefore, when a calloc failure triggers the unwind_iov cleanup branch,
we should use the local variable iov instead of msg->msg_iov.

Fixes: 753fb2ee0934 ("bpf: sockmap, add msg_peek tests to test_sockmap")
Signed-off-by: Feng Yang <yangfeng@xxxxxxxxxx>
---
tools/testing/selftests/bpf/test_sockmap.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/tools/testing/selftests/bpf/test_sockmap.c b/tools/testing/selftests/bpf/test_sockmap.c
index 3e6be455d158..aaf2050e8845 100644
--- a/tools/testing/selftests/bpf/test_sockmap.c
+++ b/tools/testing/selftests/bpf/test_sockmap.c
@@ -435,7 +435,7 @@ static int msg_alloc_iov(struct msghdr *msg,
return 0;
unwind_iov:
for (i--; i >= 0 ; i--)
- free(msg->msg_iov[i].iov_base);
+ free(iov[i].iov_base);
free(iov);
return -ENOMEM;

Thanks,

Reviewed-by: John Fastabend <john.fastabend@xxxxxxxxx>