On Sat Mar 28 18:18:09 2026 +0000, David Carlier wrote:
> npcm_video_probe() allocates the npcm_video structure with kzalloc_obj()
> but never frees it on any probe error path or in npcm_video_remove(),
> leaking the allocation on every failed probe and every normal unbind.
> 
> Additionally, when npcm_video_setup_video() fails, the reserved memory
> association established by of_reserved_mem_device_init() in
> npcm_video_init() is not released, leaking the rmem_assigned_device
> entry on the global list.
> 
> Fix both by adding kfree(video) to all probe error paths and to
> npcm_video_remove(), and adding the missing
> of_reserved_mem_device_release() call when npcm_video_setup_video()
> fails.
> 
> Fixes: 46c15a4ff1f4 ("media: nuvoton: Add driver for NPCM video capture and 
> encoding engine")
> Cc: [email protected]
> Signed-off-by: David Carlier <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>

Patch committed.

Thanks,
Hans Verkuil

 drivers/media/platform/nuvoton/npcm-video.c | 32 +++++++++++++++++++++--------
 1 file changed, 23 insertions(+), 9 deletions(-)

---

diff --git a/drivers/media/platform/nuvoton/npcm-video.c 
b/drivers/media/platform/nuvoton/npcm-video.c
index 5c6bddfe8073..52505af35c08 100644
--- a/drivers/media/platform/nuvoton/npcm-video.c
+++ b/drivers/media/platform/nuvoton/npcm-video.c
@@ -1750,42 +1750,55 @@ static int npcm_video_probe(struct platform_device 
*pdev)
        regs = devm_platform_ioremap_resource(pdev, 0);
        if (IS_ERR(regs)) {
                dev_err(&pdev->dev, "Failed to parse VCD reg in DTS\n");
-               return PTR_ERR(regs);
+               rc = PTR_ERR(regs);
+               goto err_free;
        }
 
        video->vcd_regmap = devm_regmap_init_mmio(&pdev->dev, regs,
                                                  &npcm_video_regmap_cfg);
        if (IS_ERR(video->vcd_regmap)) {
                dev_err(&pdev->dev, "Failed to initialize VCD regmap\n");
-               return PTR_ERR(video->vcd_regmap);
+               rc = PTR_ERR(video->vcd_regmap);
+               goto err_free;
        }
 
        video->reset = devm_reset_control_get(&pdev->dev, NULL);
        if (IS_ERR(video->reset)) {
                dev_err(&pdev->dev, "Failed to get VCD reset control in DTS\n");
-               return PTR_ERR(video->reset);
+               rc = PTR_ERR(video->reset);
+               goto err_free;
        }
 
        video->gcr_regmap = syscon_regmap_lookup_by_phandle(pdev->dev.of_node,
                                                            "nuvoton,sysgcr");
-       if (IS_ERR(video->gcr_regmap))
-               return PTR_ERR(video->gcr_regmap);
+       if (IS_ERR(video->gcr_regmap)) {
+               rc = PTR_ERR(video->gcr_regmap);
+               goto err_free;
+       }
 
        video->gfx_regmap = syscon_regmap_lookup_by_phandle(pdev->dev.of_node,
                                                            "nuvoton,sysgfxi");
-       if (IS_ERR(video->gfx_regmap))
-               return PTR_ERR(video->gfx_regmap);
+       if (IS_ERR(video->gfx_regmap)) {
+               rc = PTR_ERR(video->gfx_regmap);
+               goto err_free;
+       }
 
        rc = npcm_video_init(video);
        if (rc)
-               return rc;
+               goto err_free;
 
        rc = npcm_video_setup_video(video);
        if (rc)
-               return rc;
+               goto err_release_mem;
 
        dev_info(video->dev, "NPCM video driver probed\n");
        return 0;
+
+err_release_mem:
+       of_reserved_mem_device_release(&pdev->dev);
+err_free:
+       kfree(video);
+       return rc;
 }
 
 static void npcm_video_remove(struct platform_device *pdev)
@@ -1800,6 +1813,7 @@ static void npcm_video_remove(struct platform_device 
*pdev)
        v4l2_device_unregister(v4l2_dev);
        if (video->ece.enable)
                npcm_video_ece_stop(video);
+       kfree(video);
        of_reserved_mem_device_release(dev);
 }
 
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to