[PATCH v5 4/6] qnx6: clear sb_buf after brelse in qnx6_mmi_fill_super()

From: Hui Peng

Date: Wed Sep 30 2026 - 04:22:39 EST


In qnx6_mmi_fill_super(), when superblock verification fails, brelse() is
called on unselected candidate superblocks, but their buffer pointers are
left set in local variables.

Defensively clear sb_buf pointers after calling brelse() in
qnx6_mmi_fill_super().

Fixes: 3377755f1064 ("qnx6: add support for MMI (MME) media filesystem variant")
Cc: stable@xxxxxxxxxxxxxxx
Assisted-by: LLM
Signed-off-by: Hui Peng <benquike@xxxxxxxxx>
---
Changes in v5:
- Updated commit description to clarify that clearing sb_buf pointers after
brelse() is a defensive cleanup measure per Matthias Goergens.

fs/qnx6/super_mmi.c | 3 +++
1 file changed, 3 insertions(+)

diff --git a/fs/qnx6/super_mmi.c b/fs/qnx6/super_mmi.c
index a8b512c09890..19f123d45678 100644
--- a/fs/qnx6/super_mmi.c
+++ b/fs/qnx6/super_mmi.c
@@ -102,9 +102,12 @@ struct qnx6_super_block *qnx6_mmi_fill_super(struct super_block *s, int silent)
if (fs64_to_cpu(sbi, sb1->sb_serial) >=
fs64_to_cpu(sbi, sb2->sb_serial)) {
/* superblock #1 active */
sbi->sb_buf = bh1;
sbi->sb = sb1;
brelse(bh2);
+ bh2 = NULL;
} else {
/* superblock #2 active */
sbi->sb_buf = bh2;
sbi->sb = sb2;
brelse(bh1);
+ bh1 = NULL;
}
--
2.47.3