[PATCH] ACPI: FPDT: unmap header on signature mismatch
From: raoxu
Date: Fri Jul 31 2026 - 02:46:10 EST
From: Xu Rao <raoxu@xxxxxxxxxxxxx>
fpdt_process_subtable() first maps the FPDT subtable header to verify
that the signature matches the type of the pointer record and to obtain
the full subtable length.
If malformed firmware supplies a subtable with an unexpected signature,
the function returns -EINVAL without dropping the mapping reference
acquired for the header. The normal validation path does drop this
reference before mapping the complete subtable.
This path is only reached for inconsistent firmware data and FPDT is
initialized once during boot, so the leak is unlikely to be noticed in
normal testing.
Unmap the header before returning from the signature-mismatch path.
Fixes: d1eb86e59be0 ("ACPI: tables: introduce support for FPDT table")
Signed-off-by: Xu Rao <raoxu@xxxxxxxxxxxxx>
---
drivers/acpi/acpi_fpdt.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/acpi/acpi_fpdt.c b/drivers/acpi/acpi_fpdt.c
index e75dd28d31a9..e2acaff76e77 100644
--- a/drivers/acpi/acpi_fpdt.c
+++ b/drivers/acpi/acpi_fpdt.c
@@ -182,6 +182,7 @@ static int fpdt_process_subtable(u64 address, u32 subtable_type)
if (strncmp((char *)&subtable_header->signature, signature, 4)) {
pr_info(FW_BUG "subtable signature and type mismatch!\n");
+ acpi_os_unmap_memory(subtable_header, sizeof(*subtable_header));
return -EINVAL;
}
--
2.50.1