net: phy: clean the sfp upstream if phy probing fails
Published Jun 25, 2026
8.8
HIGHCVSS 3.1
EPSS 0.25%
Description
Sashiko reported that we don't call sfp_bus_del_upstream() in the probe failure path, so let's add it, otherwise the sfp-bus is left with a dangling 'upstream' field, that may be used later on during SFP events.
This issue existed before the generic phylib sfp support, back when drivers were calling phy_sfp_probe themselves.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.5StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.5
- Version 6.12.94StatusunaffectedConstraints<=6.12.*
- Version 6.18.36StatusunaffectedConstraints<=6.18.*
- Version 6.6.143StatusunaffectedConstraints<=6.6.*
- Version 7.0.13StatusunaffectedConstraints<=7.0.*
- Version 7.1StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 5.5 · < 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
No data.
Red Hat Enterprise Linux 10
kernel
Fix deferred
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Fix deferred
Red Hat Enterprise Linux 8
kernel-rt
Fix deferred
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (10)
- https://access.redhat.com/security/cve/CVE-2026-53232 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2492782 Issue Tracking
- https://git.kernel.org/stable/c/0b27701ce93161d7bbf4b25fa20ca59963b0e20c
- https://git.kernel.org/stable/c/12fb84dc4dc8eb47ebe2b27f7de6255a4a205e1b
- https://git.kernel.org/stable/c/3a254779c169954fe23328a1db51f67be374f913
- https://git.kernel.org/stable/c/48774e87bbaa0056819d4b52301e4692e50e3252 Patch
- https://git.kernel.org/stable/c/9326b654f90a09eadeb796c82801a5609d57f0c8
- https://lore.kernel.org/linux-cve-announce/2026062508-CVE-2026-53232-1b49@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-53232
- https://www.cve.org/CVERecord?id=CVE-2026-53232
Change history (0)
No recorded changes yet.