[PATCH 1/3] ti_sci: Prevent memory leak

Andrew Goodbody andrew.goodbody at linaro.org
Mon Oct 6 17:19:59 CEST 2025


temp is assigned the pointer returned by malloc which is used without a
NULL check and then never freed. Add a NULL check and ensure temp is
freed on all return paths.

This issue was found by Smatch.

Signed-off-by: Andrew Goodbody <andrew.goodbody at linaro.org>
---
 drivers/firmware/ti_sci.c | 16 +++++++++++++---
 1 file changed, 13 insertions(+), 3 deletions(-)

diff --git a/drivers/firmware/ti_sci.c b/drivers/firmware/ti_sci.c
index 8013afef304dfb70ab14150ddc49d43ebebb5902..f262da188f675b95ae217df418dc6df0364b4425 100644
--- a/drivers/firmware/ti_sci.c
+++ b/drivers/firmware/ti_sci.c
@@ -3084,17 +3084,24 @@ devm_ti_sci_get_of_resource(const struct ti_sci_handle *handle,
 		return ERR_PTR(sets);
 	}
 	temp = malloc(sets);
+	if (!temp)
+		return ERR_PTR(-ENOMEM);
+
 	sets /= sizeof(u32);
 	res->sets = sets;
 
 	res->desc = devm_kcalloc(dev, res->sets, sizeof(*res->desc),
 				 GFP_KERNEL);
-	if (!res->desc)
+	if (!res->desc) {
+		free(temp);
 		return ERR_PTR(-ENOMEM);
+	}
 
 	ret = dev_read_u32_array(dev, of_prop, temp, res->sets);
-	if (ret)
+	if (ret) {
+		free(temp);
 		return ERR_PTR(-EINVAL);
+	}
 
 	for (i = 0; i < res->sets; i++) {
 		resource_subtype = temp[i];
@@ -3119,10 +3126,13 @@ devm_ti_sci_get_of_resource(const struct ti_sci_handle *handle,
 		res->desc[i].res_map =
 			devm_kzalloc(dev, BITS_TO_LONGS(res->desc[i].num) *
 				     sizeof(*res->desc[i].res_map), GFP_KERNEL);
-		if (!res->desc[i].res_map)
+		if (!res->desc[i].res_map) {
+			free(temp);
 			return ERR_PTR(-ENOMEM);
+		}
 	}
 
+	free(temp);
 	if (valid_set)
 		return res;
 

-- 
2.47.3



More information about the U-Boot mailing list