diff options
author | Klaus Jensen <k.jensen@samsung.com> | 2023-04-11 20:54:44 +0200 |
---|---|---|
committer | Klaus Jensen <k.jensen@samsung.com> | 2023-04-12 12:03:09 +0200 |
commit | 4b32319cdacd99be983e1a74128289ef52c5964e (patch) | |
tree | 7b82d790f41d2aa1dc9e3f25777a18e9fae68ee3 | |
parent | cb16e5c76f4e719e6d0f9fd2cb6cfe6e6c17fed9 (diff) | |
download | qemu-4b32319cdacd99be983e1a74128289ef52c5964e.zip qemu-4b32319cdacd99be983e1a74128289ef52c5964e.tar.gz qemu-4b32319cdacd99be983e1a74128289ef52c5964e.tar.bz2 |
hw/nvme: fix memory leak in nvme_dsm
The iocb (and the allocated memory to hold LBA ranges) leaks if reading
the LBA ranges fails.
Fix this by adding a free and an unref of the iocb.
Reported-by: Coverity (CID 1508281)
Fixes: d7d1474fd85d ("hw/nvme: reimplement dsm to allow cancellation")
Reviewed-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Signed-off-by: Klaus Jensen <k.jensen@samsung.com>
-rw-r--r-- | hw/nvme/ctrl.c | 3 |
1 files changed, 3 insertions, 0 deletions
diff --git a/hw/nvme/ctrl.c b/hw/nvme/ctrl.c index 8b7be14..ac24eeb 100644 --- a/hw/nvme/ctrl.c +++ b/hw/nvme/ctrl.c @@ -2619,6 +2619,9 @@ static uint16_t nvme_dsm(NvmeCtrl *n, NvmeRequest *req) status = nvme_h2c(n, (uint8_t *)iocb->range, sizeof(NvmeDsmRange) * nr, req); if (status) { + g_free(iocb->range); + qemu_aio_unref(iocb); + return status; } |