[PATCH] fs: autofs: fix memory leak in autofs_fill_super()
From: Jeffin Philip
Date: Thu Sep 03 2026 - 04:19:20 EST
In autofs_fill_super(), we create a new inode using
autofs_new_ino(), however, if we fail to create root_inode,
(that is, root_inode failure path), we return -ENOMEM without
freeing the new inode(ino) that we created causing a memory leak.
Fix this by adding autofs_free_ino() to free the inode we created
in root_inode failure path before returning ENOMEM.
Reported-by: syzbot+df1db6e034b3953e19f5@xxxxxxxxxxxxxxxxxxxxxxxxx
Closes: https://syzkaller.appspot.com/bug?extid=df1db6e034b3953e19f5
Fixes: 66917f85db60 ("autofs: add: new_inode check in autofs_fill_super()")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Jeffin Philip <jeffinphilip14@xxxxxxxxx>
---
fs/autofs/inode.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/fs/autofs/inode.c b/fs/autofs/inode.c
index c1e210cec436..6b15a3717ba7 100644
--- a/fs/autofs/inode.c
+++ b/fs/autofs/inode.c
@@ -323,8 +323,10 @@ static int autofs_fill_super(struct super_block *s, struct fs_context *fc)
return -ENOMEM;
root_inode = autofs_get_inode(s, S_IFDIR | 0755);
- if (!root_inode)
+ if (!root_inode) {
+ autofs_free_ino(ino);
return -ENOMEM;
+ }
root_inode->i_uid = ctx->uid;
root_inode->i_gid = ctx->gid;
--
2.55.0