ext4: fix memory leak in parse_apply_sb_mount_options()
authorEric Biggers <ebiggers@google.com>
Fri, 13 May 2022 23:16:01 +0000 (16:16 -0700)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Thu, 9 Jun 2022 08:26:19 +0000 (10:26 +0200)
commit c069db76ed7b681c69159f44be96d2137e9ca989 upstream.

If processing the on-disk mount options fails after any memory was
allocated in the ext4_fs_context, e.g. s_qf_names, then this memory is
leaked.  Fix this by calling ext4_fc_free() instead of kfree() directly.

Reproducer:

    mkfs.ext4 -F /dev/vdc
    tune2fs /dev/vdc -E mount_opts=usrjquota=file
    echo clear > /sys/kernel/debug/kmemleak
    mount /dev/vdc /vdc
    echo scan > /sys/kernel/debug/kmemleak
    sleep 5
    echo scan > /sys/kernel/debug/kmemleak
    cat /sys/kernel/debug/kmemleak

Fixes: 7edfd85b1ffd ("ext4: Completely separate options parsing and sb setup")
Cc: stable@vger.kernel.org
Signed-off-by: Eric Biggers <ebiggers@google.com>
Tested-by: Ritesh Harjani <ritesh.list@gmail.com>
Link: https://lore.kernel.org/r/20220513231605.175121-2-ebiggers@kernel.org
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
fs/ext4/super.c

index b2210e9e431f30e8524fb846f6cb4894b12ca56c..ddd924dc0fc34203ed55c8accd6acf9f78a09993 100644 (file)
@@ -2626,8 +2626,10 @@ static int parse_apply_sb_mount_options(struct super_block *sb,
        ret = ext4_apply_options(fc, sb);
 
 out_free:
-       kfree(s_ctx);
-       kfree(fc);
+       if (fc) {
+               ext4_fc_free(fc);
+               kfree(fc);
+       }
        kfree(s_mount_opts);
        return ret;
 }