Re: [PATCH] net: sfp: Fix memory leak of hwmon_name on hwmon registration failure

krishan mohan <[email protected]>
Newsgroups gmane.linux.network,gmane.linux.kernel
Message-ID <CAAvqt3s1Tt9zM9vUO1-khbRPLX=fQbPaDsG_Xyd3t87reyWvNQ@mail.gmail.com>
Hi All,

Please find v2 of this patch.
Changes since v1: - Move hwmon_name cleanup to sfp_hwmon_remove(). - Free
hwmon_name independently of hwmon_dev.

---
v2:
- Move hwmon_name cleanup to sfp_hwmon_remove().
- Free hwmon_name independently of hwmon_dev.
---
 drivers/net/phy/sfp.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/drivers/net/phy/sfp.c b/drivers/net/phy/sfp.c
index f52020673..bfa2b821f 100644
--- a/drivers/net/phy/sfp.c
+++ b/drivers/net/phy/sfp.c
@@ -1916,7 +1916,11 @@ static void sfp_hwmon_remove(struct sfp *sfp)
  if (!IS_ERR_OR_NULL(sfp->hwmon_dev)) {
  hwmon_device_unregister(sfp->hwmon_dev);
  sfp->hwmon_dev = NULL;
+ }
+
+ if (!IS_ERR_OR_NULL(sfp->hwmon_name)) {
  kfree(sfp->hwmon_name);
+ sfp->hwmon_name = NULL;
  }
 }

-- 


Thanks&Regards
Krishan Mohan Singh


On Wed, Aug 5, 2026 at 5:28 PM Andrew Lunn <[email protected]> wrote:

> On Wed, Aug 05, 2026 at 10:06:43AM +0530, Krishan Singh wrote:
> >     hwmon_sanitize_name() allocates sfp->hwmon_name before
> >     hwmon_device_register_with_info() is called. If the registration
> >     fails, sfp->hwmon_dev is left as an error pointer while
> >     sfp->hwmon_name remains allocated.
> >
> >     Later, when the SFP module is removed, sfp_hwmon_remove() is still
> >     called. However, it frees sfp->hwmon_name only when
> >     !IS_ERR_OR_NULL(sfp->hwmon_dev) is true. Since sfp->hwmon_dev is an
> >     error pointer in the failure case, the cleanup block is skipped and
> >     hwmon_name is leaked.
> >
> >     Fix this by cleaning up hwmon_name independently of hwmon_dev.
> >     Continue to unregister the hwmon device only when hwmon_dev is valid,
> >     but free hwmon_name whenever it is a valid allocated pointer.
> >
> >     Fixes: 3f118c449c8e ("net: sfp: use hwmon_sanitize_name()")
> >     Suggested-by: Andrew Lunn <[email protected]>
> >     Signed-off-by: Krishan Singh <[email protected]>
> > ---
>
> Please read
>
> https://docs.kernel.org/process/submitting-patches.html
>
> There should be a version number in the Subject: line, and under the
> --- a version history.
>
> https://www.kernel.org/doc/html/latest/process/maintainer-netdev.html
>
> For netdev, we want the tree to be indicated in the Subject: line. For
> this patch i would suggest net-next.
>
>     Andrew
>
> ---
> pw-bot: cr
>
v2-0001-net-sfp-fix-hwmon_name-memory-leak-on-hwmon-regis.patch (text/x-patch, 1.5 KB)
From 9aab7f7e86228f708a9a968b756c83516b0ce817 Mon Sep 17 00:00:00 2001
From: Krishan Singh <[email protected]>
Date: Wed, 5 Aug 2026 10:04:47 +0530
Subject: [PATCH net-next v2] net: sfp: fix hwmon_name memory leak on hwmon
 registration failure

hwmon_sanitize_name() allocates sfp->hwmon_name before
hwmon_device_register_with_info() is called. If the registration
fails, sfp->hwmon_dev is left pointing to an error while
sfp->hwmon_name remains allocated.

Later, when the SFP module is removed, sfp_hwmon_remove() only frees
hwmon_name when hwmon_dev is valid. As a result, hwmon_name is leaked
if hwmon_device_register_with_info() fails.

Free hwmon_name independently of hwmon_dev. Continue to unregister the
hwmon device only when hwmon_dev was successfully registered.

Fixes: 3f118c449c8e ("net: sfp: use hwmon_sanitize_name()")
Suggested-by: Andrew Lunn <[email protected]>
Signed-off-by: Krishan Singh <[email protected]>

---
v2:
- Move hwmon_name cleanup to sfp_hwmon_remove().
- Free hwmon_name independently of hwmon_dev.
---
 drivers/net/phy/sfp.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/drivers/net/phy/sfp.c b/drivers/net/phy/sfp.c
index f52020673..bfa2b821f 100644
--- a/drivers/net/phy/sfp.c
+++ b/drivers/net/phy/sfp.c
@@ -1916,7 +1916,11 @@ static void sfp_hwmon_remove(struct sfp *sfp)
 	if (!IS_ERR_OR_NULL(sfp->hwmon_dev)) {
 		hwmon_device_unregister(sfp->hwmon_dev);
 		sfp->hwmon_dev = NULL;
+	}
+
+	if (!IS_ERR_OR_NULL(sfp->hwmon_name)) {
 		kfree(sfp->hwmon_name);
+		sfp->hwmon_name = NULL;
 	}
 }
 
-- 
2.34.1
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.