[PATCH] tty: vt: fix memory leak in vc_allocate()
From: Mingyu Wang
Date: Thu Jul 23 2026 - 03:13:33 EST
If the screen buffer allocation fails in vc_allocate(), the error handling
path jumps to `err_free`. However, this path fails to release the unicode
screen map attached to `vc->uni_pagedict_loc`.
During the early stages of vc_allocate(), the unicode screen map is either
newly allocated via con_set_default_unimap() or shares the default unicode
map from a previously initialized console (which increments its refcount).
If the subsequent kzalloc() for the screen buffer fails, the err_free path
frees the vc structure but leaves the attached uni_pagedict with an
elevated refcount. This results in a memory leak if that console is later
deallocated.
Fix this by calling con_free_unimap(vc) in the err_free path before
kfree(vc). This safely decrements the refcount and releases the dictionary
memory if this was the last reference.
Fixes: 34902b7f2754 ("tty: vt, get rid of weird source code flow")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Mingyu Wang <25181214217@xxxxxxxxxxxxxxxxx>
---
drivers/tty/vt/vt.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/tty/vt/vt.c b/drivers/tty/vt/vt.c
index 8f467b22b799..4bac89ea968a 100644
--- a/drivers/tty/vt/vt.c
+++ b/drivers/tty/vt/vt.c
@@ -1134,6 +1134,7 @@ int vc_allocate(unsigned int currcons) /* return 0 on success */
return 0;
err_free:
visual_deinit(vc);
+ con_free_unimap(vc);
kfree(vc);
vc_cons[currcons].d = NULL;
return err;
--
2.34.1