« Volver al listado

CVE-2026-72391

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy

sfp_i2c_mdiobus_create() allocates the I2C MDIO bus with mdio_i2c_alloc(), a plain (non-devm) allocation, and registers it. sfp_i2c_mdiobus_destroy() only unregisters the bus and clears sfp->i2c_mii without calling mdiobus_free(). As the only reference to the bus is then cleared, the struct mii_bus is leaked.

This is hit whenever a copper/RollBall SFP module that instantiated an MDIO bus is removed: sfp_sm_main() takes the global teardown path and calls sfp_i2c_mdiobus_destroy(). sfp_cleanup(), on driver unbind, frees sfp->i2c_mii directly, which is why the leak only triggered on module hot-removal and not on unbind.

Leer descripción completaMostrar menos

Free the bus in sfp_i2c_mdiobus_destroy() to match the allocation done in sfp_i2c_mdiobus_create().

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-72391",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "e85b1347ace677c3822c12d9332dfaaffe594da6",
              "lessThan": "92dd9a522f01ef57f633a8c1953cf6d48ef2bcd5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e85b1347ace677c3822c12d9332dfaaffe594da6",
              "lessThan": "d2c37f26d1a37f8177be5f354537f8ee3ec31cc2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e85b1347ace677c3822c12d9332dfaaffe594da6",
              "lessThan": "3183b6f5510c876a1c4b4a6bdc3d0ad8940fe742",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e85b1347ace677c3822c12d9332dfaaffe594da6",
              "lessThan": "86d379fcf1b79bdf4bc2ac891297f30f63d041d8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e85b1347ace677c3822c12d9332dfaaffe594da6",
              "lessThan": "2381bf3f484e8e4fd89a225445872ec14e036ab5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e85b1347ace677c3822c12d9332dfaaffe594da6",
              "lessThan": "8f31efff9206f9f0adb853cad6916086aac4d5ef",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/net/phy/sfp.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.1"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.1",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.1.178",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.97",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/net/phy/sfp.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T06:22:12.627",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/2381bf3f484e8e4fd89a225445872ec14e036ab5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3183b6f5510c876a1c4b4a6bdc3d0ad8940fe742",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/86d379fcf1b79bdf4bc2ac891297f30f63d041d8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8f31efff9206f9f0adb853cad6916086aac4d5ef",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/92dd9a522f01ef57f633a8c1953cf6d48ef2bcd5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d2c37f26d1a37f8177be5f354537f8ee3ec31cc2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy\n\nsfp_i2c_mdiobus_create() allocates the I2C MDIO bus with mdio_i2c_alloc(),\na plain (non-devm) allocation, and registers it. sfp_i2c_mdiobus_destroy()\nonly unregisters the bus and clears sfp->i2c_mii without calling\nmdiobus_free(). As the only reference to the bus is then cleared, the\nstruct mii_bus is leaked.\n\nThis is hit whenever a copper/RollBall SFP module that instantiated an MDIO\nbus is removed: sfp_sm_main() takes the global teardown path and calls\nsfp_i2c_mdiobus_destroy(). sfp_cleanup(), on driver unbind, frees\nsfp->i2c_mii directly, which is why the leak only triggered on module\nhot-removal and not on unbind.\n\nFree the bus in sfp_i2c_mdiobus_destroy() to match the allocation done in\nsfp_i2c_mdiobus_create()."
    }
  ],
  "lastModified": "2026-08-17T06:19:05.587",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}