Re: [PATCH 6.1.y] Fix memory leak in io_wq_create() on success path
From: Greg KH
Date: Thu Aug 06 2026 - 10:33:27 EST
On Thu, Aug 06, 2026 at 10:23:14PM +0800, Chen Xiaokun wrote:
> The commit 657ca82526d0 introduced a temporary allowed_mask cpumask in
> io_wq_create(), which was freed only on the error path. This caused a
> memory leak of cpumask_size() bytes on every successful io_wq_create().
>
> Fixes: 657ca82526d0 ("io_uring/io-wq: inherit cpuset of cgroup in io worker")
> Signed-off-by: Chen Xiaokun <shinnkka1@xxxxxxxxx>
> ---
> io_uring/io-wq.c | 1 +
> 1 file changed, 1 insertion(+)
>
> diff --git a/io_uring/io-wq.c b/io_uring/io-wq.c
> index 66fdd69fd6cb..34a1a9067cc2 100644
> --- a/io_uring/io-wq.c
> +++ b/io_uring/io-wq.c
> @@ -1218,6 +1218,7 @@ struct io_wq *io_wq_create(unsigned bounded, struct io_wq_data *data)
> wq->task = get_task_struct(data->task);
> atomic_set(&wq->worker_refs, 1);
> init_completion(&wq->worker_done);
> + free_cpumask_var(allowed_mask);
> return wq;
> err:
> io_wq_put_hash(data->hash);
> --
> 2.55.0
>
>
Why is this a stable-only patch? Was the backport wrong? Or is this
also in Linus's tree?
thanks,
greg k-h