CVE-2026-53232 PUBLISHED

net: phy: clean the sfp upstream if phy probing fails

Assigner: Linux
Reserved: 09.06.2026 Published: 25.06.2026 Updated: 25.06.2026

In the Linux kernel, the following vulnerability has been resolved:

net: phy: clean the sfp upstream if phy probing fails

Sashiko reported that we don't call sfp_bus_del_upstream() in the probe failure path, so let's add it, otherwise the sfp-bus is left with a dangling 'upstream' field, that may be used later on during SFP events.

This issue existed before the generic phylib sfp support, back when drivers were calling phy_sfp_probe themselves.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 298e54fa810e027f1b0800d789eb862592721f08 to 48774e87bbaa0056819d4b52301e4692e50e3252 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 5.5 is affected
  • unaffected from 0 to 5.5 (excl.)
  • unaffected from 7.1 to * (incl.)

References