aboutsummaryrefslogtreecommitdiff
path: root/hw/nvme
diff options
context:
space:
mode:
authorKlaus Jensen <k.jensen@samsung.com>2023-04-11 20:54:44 +0200
committerKlaus Jensen <k.jensen@samsung.com>2023-04-12 12:03:09 +0200
commit4b32319cdacd99be983e1a74128289ef52c5964e (patch)
tree7b82d790f41d2aa1dc9e3f25777a18e9fae68ee3 /hw/nvme
parentcb16e5c76f4e719e6d0f9fd2cb6cfe6e6c17fed9 (diff)
downloadqemu-4b32319cdacd99be983e1a74128289ef52c5964e.zip
qemu-4b32319cdacd99be983e1a74128289ef52c5964e.tar.gz
qemu-4b32319cdacd99be983e1a74128289ef52c5964e.tar.bz2
hw/nvme: fix memory leak in nvme_dsm
The iocb (and the allocated memory to hold LBA ranges) leaks if reading the LBA ranges fails. Fix this by adding a free and an unref of the iocb. Reported-by: Coverity (CID 1508281) Fixes: d7d1474fd85d ("hw/nvme: reimplement dsm to allow cancellation") Reviewed-by: Philippe Mathieu-Daudé <philmd@linaro.org> Signed-off-by: Klaus Jensen <k.jensen@samsung.com>
Diffstat (limited to 'hw/nvme')
-rw-r--r--hw/nvme/ctrl.c3
1 files changed, 3 insertions, 0 deletions
diff --git a/hw/nvme/ctrl.c b/hw/nvme/ctrl.c
index 8b7be14..ac24eeb 100644
--- a/hw/nvme/ctrl.c
+++ b/hw/nvme/ctrl.c
@@ -2619,6 +2619,9 @@ static uint16_t nvme_dsm(NvmeCtrl *n, NvmeRequest *req)
status = nvme_h2c(n, (uint8_t *)iocb->range, sizeof(NvmeDsmRange) * nr,
req);
if (status) {
+ g_free(iocb->range);
+ qemu_aio_unref(iocb);
+
return status;
}