Re: [PATCH] staging: vme_user: fix flush_image leak in tsi148 bridge
From: Nguyễn Công
Date: Thu Aug 13 2026 - 07:31:55 EST
On Wed, Aug 12, 2026 at 7:25 AM Greg Kroah-Hartman
<gregkh@xxxxxxxxxxxxxxxxxxx> wrote:
>
> On Mon, Jul 27, 2026 at 06:15:34PM +0700, Cong Nguyen wrote:
> > When error checking is enabled (err_chk=1), tsi148_probe() allocates an
> > extra master window resource, tsi148_device->flush_image, which is used
> > to flush posted writes by reading back over the VME bus. Unlike the
> > regular master windows, this resource is not linked into
> > tsi148_bridge->master_resources.
> >
> > Because it is not on any resource list, it is freed neither by the probe
> > error path (which only walks the master_resources list) nor by
> > tsi148_remove(), so it is leaked whenever err_chk is set and either
> > probe fails after the allocation or the device is unbound / the module
> > is unloaded.
> >
> > Free flush_image in both the probe error path and tsi148_remove(). This
> > is safe when err_chk is disabled: tsi148_device is allocated with
> > kzalloc() so flush_image is NULL and kfree(NULL) is a no-op.
> >
> > Fixes: d22b8ed9a3b0 ("Staging: vme: add Tundra TSI148 VME-PCI Bridge driver")
> > Cc: stable@xxxxxxxxxxxxxxx
> > Signed-off-by: Cong Nguyen <congnt264@xxxxxxxxx>
> > ---
> > drivers/staging/vme_user/vme_tsi148.c | 3 +++
> > 1 file changed, 3 insertions(+)
>
> How was this found and tested?
Code inspection: flush_image is allocated in tsi148_probe() (when
err_chk is set) but never added to master_resources, while both the
probe error path and tsi148_remove() only free windows on that list.
Build-tested only; I have no TSI148 hardware.
>
> Did you forget an Assisted-by: tag?
Yes, sorry -- found with AI assistance and I missed the tag. I'll send a
v2 adding:
Assisted-by: Claude:claude-opus-4
>
> thanks,
>
> greg k-h
Thanks,
Cong