drivers/net/phy/sfp.c | 4 ++++ 1 file changed, 4 insertions(+)
hwmon_sanitize_name() allocates sfp->hwmon_name before
hwmon_device_register_with_info() is called. If the registration
fails, sfp->hwmon_dev is left as an error pointer while
sfp->hwmon_name remains allocated.
Later, when the SFP module is removed, sfp_hwmon_remove() is still
called. However, it frees sfp->hwmon_name only when
!IS_ERR_OR_NULL(sfp->hwmon_dev) is true. Since sfp->hwmon_dev is an
error pointer in the failure case, the cleanup block is skipped and
hwmon_name is leaked.
Fix this by cleaning up hwmon_name independently of hwmon_dev.
Continue to unregister the hwmon device only when hwmon_dev is valid,
but free hwmon_name whenever it is a valid allocated pointer.
Fixes: 3f118c449c8e ("net: sfp: use hwmon_sanitize_name()")
Suggested-by: Andrew Lunn <andrew@lunn.ch>
Signed-off-by: Krishan Singh <krishanmohan298@gmail.com>
---
drivers/net/phy/sfp.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/drivers/net/phy/sfp.c b/drivers/net/phy/sfp.c
index f52020673..bfa2b821f 100644
--- a/drivers/net/phy/sfp.c
+++ b/drivers/net/phy/sfp.c
@@ -1916,7 +1916,11 @@ static void sfp_hwmon_remove(struct sfp *sfp)
if (!IS_ERR_OR_NULL(sfp->hwmon_dev)) {
hwmon_device_unregister(sfp->hwmon_dev);
sfp->hwmon_dev = NULL;
+ }
+
+ if (!IS_ERR_OR_NULL(sfp->hwmon_name)) {
kfree(sfp->hwmon_name);
+ sfp->hwmon_name = NULL;
}
}
--
2.34.1
On Wed, Aug 05, 2026 at 10:06:43AM +0530, Krishan Singh wrote:
> hwmon_sanitize_name() allocates sfp->hwmon_name before
> hwmon_device_register_with_info() is called. If the registration
> fails, sfp->hwmon_dev is left as an error pointer while
> sfp->hwmon_name remains allocated.
>
> Later, when the SFP module is removed, sfp_hwmon_remove() is still
> called. However, it frees sfp->hwmon_name only when
> !IS_ERR_OR_NULL(sfp->hwmon_dev) is true. Since sfp->hwmon_dev is an
> error pointer in the failure case, the cleanup block is skipped and
> hwmon_name is leaked.
>
> Fix this by cleaning up hwmon_name independently of hwmon_dev.
> Continue to unregister the hwmon device only when hwmon_dev is valid,
> but free hwmon_name whenever it is a valid allocated pointer.
>
> Fixes: 3f118c449c8e ("net: sfp: use hwmon_sanitize_name()")
> Suggested-by: Andrew Lunn <andrew@lunn.ch>
> Signed-off-by: Krishan Singh <krishanmohan298@gmail.com>
> ---
Please read
https://docs.kernel.org/process/submitting-patches.html
There should be a version number in the Subject: line, and under the
--- a version history.
https://www.kernel.org/doc/html/latest/process/maintainer-netdev.html
For netdev, we want the tree to be indicated in the Subject: line. For
this patch i would suggest net-next.
Andrew
---
pw-bot: cr
Hi All,
Please find v2 of this patch.
Changes since v1: - Move hwmon_name cleanup to sfp_hwmon_remove(). - Free
hwmon_name independently of hwmon_dev.
---
v2:
- Move hwmon_name cleanup to sfp_hwmon_remove().
- Free hwmon_name independently of hwmon_dev.
---
drivers/net/phy/sfp.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/drivers/net/phy/sfp.c b/drivers/net/phy/sfp.c
index f52020673..bfa2b821f 100644
--- a/drivers/net/phy/sfp.c
+++ b/drivers/net/phy/sfp.c
@@ -1916,7 +1916,11 @@ static void sfp_hwmon_remove(struct sfp *sfp)
if (!IS_ERR_OR_NULL(sfp->hwmon_dev)) {
hwmon_device_unregister(sfp->hwmon_dev);
sfp->hwmon_dev = NULL;
+ }
+
+ if (!IS_ERR_OR_NULL(sfp->hwmon_name)) {
kfree(sfp->hwmon_name);
+ sfp->hwmon_name = NULL;
}
}
--
Thanks&Regards
Krishan Mohan Singh
On Wed, Aug 5, 2026 at 5:28 PM Andrew Lunn <andrew@lunn.ch> wrote:
> On Wed, Aug 05, 2026 at 10:06:43AM +0530, Krishan Singh wrote:
> > hwmon_sanitize_name() allocates sfp->hwmon_name before
> > hwmon_device_register_with_info() is called. If the registration
> > fails, sfp->hwmon_dev is left as an error pointer while
> > sfp->hwmon_name remains allocated.
> >
> > Later, when the SFP module is removed, sfp_hwmon_remove() is still
> > called. However, it frees sfp->hwmon_name only when
> > !IS_ERR_OR_NULL(sfp->hwmon_dev) is true. Since sfp->hwmon_dev is an
> > error pointer in the failure case, the cleanup block is skipped and
> > hwmon_name is leaked.
> >
> > Fix this by cleaning up hwmon_name independently of hwmon_dev.
> > Continue to unregister the hwmon device only when hwmon_dev is valid,
> > but free hwmon_name whenever it is a valid allocated pointer.
> >
> > Fixes: 3f118c449c8e ("net: sfp: use hwmon_sanitize_name()")
> > Suggested-by: Andrew Lunn <andrew@lunn.ch>
> > Signed-off-by: Krishan Singh <krishanmohan298@gmail.com>
> > ---
>
> Please read
>
> https://docs.kernel.org/process/submitting-patches.html
>
> There should be a version number in the Subject: line, and under the
> --- a version history.
>
> https://www.kernel.org/doc/html/latest/process/maintainer-netdev.html
>
> For netdev, we want the tree to be indicated in the Subject: line. For
> this patch i would suggest net-next.
>
> Andrew
>
> ---
> pw-bot: cr
>
On Fri, Aug 07, 2026 at 12:52:58PM +0530, krishan mohan wrote:
> Hi All,
>
> Please find v2 of this patch.
> Changes since v1: - Move hwmon_name cleanup to sfp_hwmon_remove(). - Free
> hwmon_name independently of hwmon_dev.
Please read:
https://docs.kernel.org/process/submitting-patches.html
and then submit a proper patch, following the process defined in this
document.
It is also important you start a new thread, otherwise the CI probably
does not work.
Andrew
---
pw-bot: cr
© 2016 - 2026 Red Hat, Inc.