[PATCH v3 3/6] qnx6: avoid double brelse() on error path in qnx6_fill_super()
From: Hui Peng
Date: Thu Sep 24 2026 - 03:46:11 EST
In qnx6_fill_super(), sb_buf is assigned the return value of
sb_bread(sb, 1). If parsing the primary superblock fails, execution
branches to out_sbl2, which calls brelse(sbi->sb_buf) and then falls
through to out_sbl1, which calls brelse(sb_buf) a second time on the same
buffer head pointer, causing a double free / refcount underflow.
Fix the error-handling cleanup sequence in qnx6_fill_super() to avoid
calling brelse(sb_buf) twice.
Fixes: 5d026c724220 ("fs: initial qnx6fs addition")
Cc: stable@xxxxxxxxxxxxxxx
Tested-by: Matthias Goergens <matthias.goergens@xxxxxxxxx>
Reviewed-by: Matthias Goergens <matthias.goergens@xxxxxxxxx>
Assisted-by: LLM
Signed-off-by: Hui Peng <benquike@xxxxxxxxx>
---
Changes in v3:
- Add Tested-by and Reviewed-by tags from Matthias Goergens.
- Update Fixes: tag SHA to 5d026c724220 ("fs: initial qnx6fs addition").
Changes in v2:
- Split out as patch 3/6 as requested by maintainers.
fs/qnx6/inode.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/fs/qnx6/inode.c b/fs/qnx6/inode.c
index 444458ce3e77..70438cf5efdf 100644
--- a/fs/qnx6/inode.c
+++ b/fs/qnx6/inode.c
@@ -348,7 +348,7 @@ static int qnx6_fill_super(struct super_block *s, void *data, int silent)
out_sbl2:
brelse(sbi->sb_buf);
sbi->sb_buf = NULL;
-out_sbl1:
+out_sbl1:
brelse(sb_buf);
return -EINVAL;
}
--
2.55.0.1082.g2b9226bbc0-goog