[PATCH] usb: typec: Fix PD object leak in select_usb_power_delivery_store()
From: Wentao Liang
Date: Wed Sep 16 2026 - 13:57:55 EST
select_usb_power_delivery_store() looks up the requested USB Power
Delivery object with usb_power_delivery_find(), which returns the
object with a reference taken by class_find_device_by_name(). The
reference is never dropped, neither when port->ops->pd_set() fails nor
when it succeeds, leaking a reference to the USB PD object on every
sysfs store.
Drop the reference with put_device() once the pd_set() callback has
returned and the object is no longer needed.
Fixes: a7cff92f0635 ("usb: typec: USB Power Delivery helpers for ports and partners")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Wentao Liang <vulab@xxxxxxxxxxx>
---
drivers/usb/typec/class.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/usb/typec/class.c b/drivers/usb/typec/class.c
index 0977581ad1b6..0595e8cb83aa 100644
--- a/drivers/usb/typec/class.c
+++ b/drivers/usb/typec/class.c
@@ -1619,6 +1619,7 @@ static ssize_t select_usb_power_delivery_store(struct device *dev,
return -EINVAL;
ret = port->ops->pd_set(port, pd);
+ put_device(&pd->dev);
if (ret)
return ret;
--
2.34.1