[PATCH] KVM: x86: Cancel PIT timer on failed creation
From: Bruno Produit
Date: Fri Oct 02 2026 - 11:22:35 EST
From: Kyle Zeng <kylebot@xxxxxxxxxx>
Cancel the PIT hrtimer if PIT creation fails after registering the PIO
device. This matches normal teardown and ensures the timer no longer
uses the PIT before its memory is freed.
KVM registers the PIT's PIO device before registering the optional dummy
speaker device. If speaker registration fails, a vCPU can have already
programmed channel 0 and armed pit_state.timer through the published PIT
device. When I/O bus registration became fallible, its cleanup did not
cancel the timer before freeing the PIT.
Fixes: 090b7aff2712 ("KVM: make io_bus interface more robust")
Cc: stable@xxxxxxxxxxxxxxx
Assisted-by: Codex:gpt-5.6-sol
Signed-off-by: Kyle Zeng <kylebot@xxxxxxxxxx>
Signed-off-by: Bruno Produit <bruno.produit@xxxxxxxxxxxxxxx>
---
arch/x86/kvm/i8254.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/arch/x86/kvm/i8254.c b/arch/x86/kvm/i8254.c
index 1982b0077..b7875345f 100644
--- a/arch/x86/kvm/i8254.c
+++ b/arch/x86/kvm/i8254.c
@@ -793,6 +793,7 @@ struct kvm_pit *kvm_create_pit(struct kvm *kvm, u32 flags)
fail_register_pit:
mutex_unlock(&kvm->slots_lock);
kvm_pit_set_reinject(pit, false);
+ hrtimer_cancel(&pit->pit_state.timer);
kthread_destroy_worker(pit->worker);
fail_kthread:
kfree(pit);
--
2.53.0