DORMANTno replies

[PATCH] net: sfp: Fix memory leak of hwmon_name on hwmon registration failure

From: Krishan Singh <hidden>
Date: 2026-08-05 04:24:48
Also in: lkml
Subsystem: ethernet phy library, networking drivers, sff/sfp/sfp+ module support, the rest · Maintainers: Andrew Lunn, Heiner Kallweit, Andrew Lunn, "David S. Miller", Eric Dumazet, Jakub Kicinski, Paolo Abeni, Russell King, Linus Torvalds

hwmon_sanitize_name() allocates sfp->hwmon_name before
hwmon_device_register_with_info() is called. If the registration
fails, sfp->hwmon_dev is left as an error pointer while
sfp->hwmon_name remains allocated.

Later, when the SFP module is removed, sfp_hwmon_remove() is still
called. However, it frees sfp->hwmon_name only when
!IS_ERR_OR_NULL(sfp->hwmon_dev) is true. Since sfp->hwmon_dev is an
error pointer in the failure case, the cleanup block is skipped and
hwmon_name is leaked.

Fix this by cleaning up hwmon_name independently of hwmon_dev.
Continue to unregister the hwmon device only when hwmon_dev is valid,
but free hwmon_name whenever it is a valid allocated pointer.

Fixes: 3f118c449c8e ("net: sfp: use hwmon_sanitize_name()")
Suggested-by: Andrew Lunn <andrew@lunn.ch>
Signed-off-by: Krishan Singh <redacted>
---
 drivers/net/phy/sfp.c | 6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/drivers/net/phy/sfp.c b/drivers/net/phy/sfp.c
index f52020673..f605fb399 100644
--- a/drivers/net/phy/sfp.c
+++ b/drivers/net/phy/sfp.c
@@ -1895,9 +1895,13 @@ static void sfp_hwmon_probe(struct work_struct *work)
 							 sfp->hwmon_name, sfp,
 							 &sfp_hwmon_chip_info,
 							 NULL);
-	if (IS_ERR(sfp->hwmon_dev))
+	if (IS_ERR(sfp->hwmon_dev)) {
 		dev_err(sfp->dev, "failed to register hwmon device: %ld\n",
 			PTR_ERR(sfp->hwmon_dev));
+		kfree(sfp->hwmon_name);
+		sfp->hwmon_name = NULL;
+		sfp->hwmon_dev  = NULL;
+	 }
 }
 
 static int sfp_hwmon_insert(struct sfp *sfp)
-- 
2.34.1
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help