CVE-2026-72391: net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy

Published Aug 15, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

net: phy: sfp: free miibus in sfpi2cmdiobusdestroy

sfpi2cmdiobuscreate() allocates the I2C MDIO bus with mdioi2calloc(), a plain (non-devm) allocation, and registers it. sfpi2cmdiobusdestroy() only unregisters the bus and clears sfp->i2cmii without calling mdiobusfree(). As the only reference to the bus is then cleared, the struct miibus is leaked.

This is hit whenever a copper/RollBall SFP module that instantiated an MDIO bus is removed: sfpsmmain() takes the global teardown path and calls sfpi2cmdiobusdestroy(). sfpcleanup(), on driver unbind, frees sfp->i2cmii directly, which is why the leak only triggered on module hot-removal and not on unbind.

Free the bus in sfpi2cmdiobusdestroy() to match the allocation done in sfpi2cmdiobuscreate().

Affected Software

1 affected component
Linux Linux kernel

Event History

Aug 15, 2026
CVE Published
via MITRE·05:56 AM
Data Sourced
via MITRE·05:56 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203