[PATCH 7/7] regmap: fix potential double-free of map->reg_defaults on cache reinit

From: Peng Fan (OSS)

Date: Wed Sep 30 2026 - 05:59:16 EST


From: Peng Fan <peng.fan@xxxxxxx>

regcache_exit() frees map->reg_defaults but does not NULL the pointer.
If regmap_reinit_cache() is later called with a config that has neither
reg_defaults nor num_reg_defaults_raw, regcache_init() skips both
allocation branches and leaves the stale pointer in place. Should
cache_ops->init then fail, the err_free_reg_defaults error path calls
kfree(map->reg_defaults) a second time.

NULL the pointer after freeing so the error-path kfree() is a harmless
no-op.

Assisted-by: LLM
Signed-off-by: Peng Fan <peng.fan@xxxxxxx>
---
drivers/base/regmap/regcache.c | 1 +
1 file changed, 1 insertion(+)

diff --git a/drivers/base/regmap/regcache.c b/drivers/base/regmap/regcache.c
index 136d6adf3120..3b1c2f28d585 100644
--- a/drivers/base/regmap/regcache.c
+++ b/drivers/base/regmap/regcache.c
@@ -294,6 +294,7 @@ void regcache_exit(struct regmap *map)
regcache_locked_exit(map);

kfree(map->reg_defaults);
+ map->reg_defaults = NULL;
}

/**

--
2.51.0