VYPR
High severity8.8NVD Advisory· Published Jun 25, 2026· Updated Jul 16, 2026

CVE-2026-53232

CVE-2026-53232

Description

In the Linux kernel, the following vulnerability has been resolved:

net: phy: clean the sfp upstream if phy probing fails

Sashiko reported that we don't call sfp_bus_del_upstream() in the probe failure path, so let's add it, otherwise the sfp-bus is left with a dangling 'upstream' field, that may be used later on during SFP events.

This issue existed before the generic phylib sfp support, back when drivers were calling phy_sfp_probe themselves.

Affected products

12
  • Linux/Kernelllm-fuzzy9 versions
    (expand)+ 8 more
    • (no CPE)
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=5.5,<7.1
    • cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:7.1:rc7:*:*:*:*:*:*
  • osv-coords3 versions
    >= 5.5.0, < 6.6.143+ 2 more
    • (no CPE)range: >= 5.5.0, < 6.6.143
    • (no CPE)range: < 6.18.38-r2
    • (no CPE)range: < 6.18.38-r2

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.