* [PATCH] net: usb: lan78xx: Fix URB reference leak in lan78xx_submit_deferred_urbs()
@ 2026-09-17 11:58 Wentao Liang
2026-09-22 14:00 ` patchwork-bot+netdevbpf
0 siblings, 1 reply; 2+ messages in thread
From: Wentao Liang @ 2026-09-17 11:58 UTC (permalink / raw)
To: Rengarajan.S
Cc: Thangaraj.S, UNGLinuxDriver, andrew+netdev, davem, edumazet,
john.efstathiades, kuba, linux-kernel, linux-usb, netdev, pabeni,
Wentao Liang, stable
usb_get_from_anchor() hands over a reference to the URB, which the caller
must release. lan78xx_submit_deferred_urbs() never does, so every deferred
Tx URB keeps an extra reference: the counter grows on each suspend/resume
cycle and the URBs are never freed when the buffers are released. Drop
the reference after submitting, and on the path that drops the packet
instead of submitting it.
Fixes: 5f4cc6e25148 ("lan78xx: Fix race conditions in suspend/resume handling")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
---
drivers/net/usb/lan78xx.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/net/usb/lan78xx.c b/drivers/net/usb/lan78xx.c
index bcf293ea1bd3..8e075a31d97c 100644
--- a/drivers/net/usb/lan78xx.c
+++ b/drivers/net/usb/lan78xx.c
@@ -5204,10 +5204,12 @@ static bool lan78xx_submit_deferred_urbs(struct lan78xx_net *dev)
!netif_carrier_ok(dev->net) ||
pipe_halted) {
lan78xx_release_tx_buf(dev, skb);
+ usb_put_urb(urb);
continue;
}
ret = usb_submit_urb(urb, GFP_ATOMIC);
+ usb_put_urb(urb);
if (ret == 0) {
netif_trans_update(dev->net);
--
2.34.1
^ permalink raw reply [flat|nested] 2+ messages in thread* Re: [PATCH] net: usb: lan78xx: Fix URB reference leak in lan78xx_submit_deferred_urbs()
2026-09-17 11:58 [PATCH] net: usb: lan78xx: Fix URB reference leak in lan78xx_submit_deferred_urbs() Wentao Liang
@ 2026-09-22 14:00 ` patchwork-bot+netdevbpf
0 siblings, 0 replies; 2+ messages in thread
From: patchwork-bot+netdevbpf @ 2026-09-22 14:00 UTC (permalink / raw)
To: Wentao Liang
Cc: Rengarajan.S, Thangaraj.S, UNGLinuxDriver, andrew+netdev, davem,
edumazet, john.efstathiades, kuba, linux-kernel, linux-usb,
netdev, pabeni, stable
Hello:
This patch was applied to netdev/net.git (main)
by Paolo Abeni <pabeni@redhat.com>:
On Thu, 17 Sep 2026 11:58:11 +0000 you wrote:
> usb_get_from_anchor() hands over a reference to the URB, which the caller
> must release. lan78xx_submit_deferred_urbs() never does, so every deferred
> Tx URB keeps an extra reference: the counter grows on each suspend/resume
> cycle and the URBs are never freed when the buffers are released. Drop
> the reference after submitting, and on the path that drops the packet
> instead of submitting it.
>
> [...]
Here is the summary with links:
- net: usb: lan78xx: Fix URB reference leak in lan78xx_submit_deferred_urbs()
https://git.kernel.org/netdev/net/c/17741334d00b
You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-09-22 14:01 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-17 11:58 [PATCH] net: usb: lan78xx: Fix URB reference leak in lan78xx_submit_deferred_urbs() Wentao Liang
2026-09-22 14:00 ` patchwork-bot+netdevbpf
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®