[PATCH v2] usb: dwc2: debugfs: fix memory leak of hsotg->regset

From: Huang Wei

Date: Tue Sep 08 2026 - 22:10:53 EST


hsotg->regset is allocated in dwc2_debugfs_init() using devm_kzalloc(),
which ties its lifetime to the device (struct dwc2_hsotg) rather than
to the debugfs entries it serves. dwc2_debugfs_exit() removes the
debugfs directory but leaves hsotg->regset allocated until the device
itself is removed, so the pointer dangles for the remainder of the
device lifetime.

Switch to kzalloc() and free it explicitly in dwc2_debugfs_exit() so
the regset lifetime matches the debugfs lifetime. Set the pointer to
NULL after freeing to avoid a stale dangling pointer.

Reported-by: kakapapa2 <kakapapa2@xxxxxxxxx>
Closes: https://bugzilla.kernel.org/show_bug.cgi?id=219977
Reviewed-by: Thinh Nguyen <Thinh.Nguyen@xxxxxxxxxxxx>
Signed-off-by: Huang Wei <huangwei@xxxxxxxxxx>

---
Changes in v2:
- Rework the commit message per Thinh Nguyen: the issue is an
allocation lifetime mismatch with the debugfs lifetime, not a
traditional memory leak (the devm_kzalloc() allocation is
eventually reclaimed by devres). Drop the misleading reference to the
dwc3 regset commit, which addressed a separate problem.
---
drivers/usb/dwc2/debugfs.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)

diff --git a/drivers/usb/dwc2/debugfs.c b/drivers/usb/dwc2/debugfs.c
index 3116ac72747f..2ecbf6523aaa 100644
--- a/drivers/usb/dwc2/debugfs.c
+++ b/drivers/usb/dwc2/debugfs.c
@@ -9,6 +9,7 @@
#include <linux/spinlock.h>
#include <linux/debugfs.h>
#include <linux/seq_file.h>
+#include <linux/slab.h>
#include <linux/uaccess.h>

#include "core.h"
@@ -787,8 +788,7 @@ int dwc2_debugfs_init(struct dwc2_hsotg *hsotg)
/* Add gadget debugfs nodes */
dwc2_hsotg_create_debug(hsotg);

- hsotg->regset = devm_kzalloc(hsotg->dev, sizeof(*hsotg->regset),
- GFP_KERNEL);
+ hsotg->regset = kzalloc_obj(*hsotg->regset, GFP_KERNEL);
if (!hsotg->regset) {
ret = -ENOMEM;
goto err;
@@ -810,4 +810,6 @@ void dwc2_debugfs_exit(struct dwc2_hsotg *hsotg)
{
debugfs_remove_recursive(hsotg->debug_root);
hsotg->debug_root = NULL;
+ kfree(hsotg->regset);
+ hsotg->regset = NULL;
}
--
2.25.1