Re: [PATCH] usb: typec: Fix PD object leak in select_usb_power_delivery_store()

From: Heikki Krogerus

Date: Fri Sep 18 2026 - 06:03:11 EST


On Wed, Sep 16, 2026 at 05:01:39PM +0000, Wentao Liang wrote:
> select_usb_power_delivery_store() looks up the requested USB Power
> Delivery object with usb_power_delivery_find(), which returns the
> object with a reference taken by class_find_device_by_name(). The
> reference is never dropped, neither when port->ops->pd_set() fails nor
> when it succeeds, leaking a reference to the USB PD object on every
> sysfs store.
>
> Drop the reference with put_device() once the pd_set() callback has
> returned and the object is no longer needed.
>
> Fixes: a7cff92f0635 ("usb: typec: USB Power Delivery helpers for ports and partners")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Wentao Liang <vulab@xxxxxxxxxxx>

There seems to already be a fix for this:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=43ae2f90b70cda374c487c1639a01d0f14e5d583

Thanks,

> ---
> drivers/usb/typec/class.c | 1 +
> 1 file changed, 1 insertion(+)
>
> diff --git a/drivers/usb/typec/class.c b/drivers/usb/typec/class.c
> index 0977581ad1b6..0595e8cb83aa 100644
> --- a/drivers/usb/typec/class.c
> +++ b/drivers/usb/typec/class.c
> @@ -1619,6 +1619,7 @@ static ssize_t select_usb_power_delivery_store(struct device *dev,
> return -EINVAL;
>
> ret = port->ops->pd_set(port, pd);
> + put_device(&pd->dev);
> if (ret)
> return ret;
>
> --
> 2.34.1

--
heikki