Re: [PATCH v2] xfs: Fix a memory leak in xfs_buf_item_init()

From: Carlos Maiolino
Date: Thu Dec 11 2025 - 04:19:03 EST


On Wed, Dec 10, 2025 at 05:06:01PM +0800, Haoxiang Li wrote:
> xfs_buf_item_get_format() may allocate memory for bip->bli_formats,
> free the memory in the error path.
>
> Fixes: c3d5f0c2fb85 ("xfs: complain if anyone tries to create a too-large buffer log item")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Haoxiang Li <lihaoxiang@xxxxxxxxxxxxxxxx>
> Reviewed-by: Christoph Hellwig <hch@xxxxxx>
> ---
> Changes in v2:
> - Modify the patch subject. Thanks, Christoph!
> ---
> fs/xfs/xfs_buf_item.c | 1 +
> 1 file changed, 1 insertion(+)
>

We have a cosmetic 'rule' to not use an Upper case character for the
subject, I'll fix that during commit time, no need to send it again.

for the patch itself:

Reviewed-by: Carlos Maiolino <cmaiolino@xxxxxxxxxx>


> diff --git a/fs/xfs/xfs_buf_item.c b/fs/xfs/xfs_buf_item.c
> index 8d85b5eee444..f4c5be67826e 100644
> --- a/fs/xfs/xfs_buf_item.c
> +++ b/fs/xfs/xfs_buf_item.c
> @@ -896,6 +896,7 @@ xfs_buf_item_init(
> map_size = DIV_ROUND_UP(chunks, NBWORD);
>
> if (map_size > XFS_BLF_DATAMAP_SIZE) {
> + xfs_buf_item_free_format(bip);
> kmem_cache_free(xfs_buf_item_cache, bip);
> xfs_err(mp,
> "buffer item dirty bitmap (%u uints) too small to reflect %u bytes!",
> --
> 2.25.1
>