* [PATCH] net: sfp: Fix memory leak of hwmon_name on hwmon registration failure
@ 2026-08-05 4:24 Krishan Singh
0 siblings, 0 replies; 5+ messages in thread
From: Krishan Singh @ 2026-08-05 4:24 UTC (permalink / raw)
To: linux
Cc: andrew, hkallweit1, davem, edumazet, kuba, pabeni, netdev,
linux-kernel, Krishan Singh
hwmon_sanitize_name() allocates sfp->hwmon_name before
hwmon_device_register_with_info() is called. If the registration
fails, sfp->hwmon_dev is left as an error pointer while
sfp->hwmon_name remains allocated.
Later, when the SFP module is removed, sfp_hwmon_remove() is still
called. However, it frees sfp->hwmon_name only when
!IS_ERR_OR_NULL(sfp->hwmon_dev) is true. Since sfp->hwmon_dev is an
error pointer in the failure case, the cleanup block is skipped and
hwmon_name is leaked.
Fix this by cleaning up hwmon_name independently of hwmon_dev.
Continue to unregister the hwmon device only when hwmon_dev is valid,
but free hwmon_name whenever it is a valid allocated pointer.
Fixes: 3f118c449c8e ("net: sfp: use hwmon_sanitize_name()")
Suggested-by: Andrew Lunn <andrew@lunn.ch>
Signed-off-by: Krishan Singh <krishanmohan298@gmail.com>
---
drivers/net/phy/sfp.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/drivers/net/phy/sfp.c b/drivers/net/phy/sfp.c
index f52020673..f605fb399 100644
--- a/drivers/net/phy/sfp.c
+++ b/drivers/net/phy/sfp.c
@@ -1895,9 +1895,13 @@ static void sfp_hwmon_probe(struct work_struct *work)
sfp->hwmon_name, sfp,
&sfp_hwmon_chip_info,
NULL);
- if (IS_ERR(sfp->hwmon_dev))
+ if (IS_ERR(sfp->hwmon_dev)) {
dev_err(sfp->dev, "failed to register hwmon device: %ld\n",
PTR_ERR(sfp->hwmon_dev));
+ kfree(sfp->hwmon_name);
+ sfp->hwmon_name = NULL;
+ sfp->hwmon_dev = NULL;
+ }
}
static int sfp_hwmon_insert(struct sfp *sfp)
--
2.34.1
^ permalink raw reply related [flat|nested] 5+ messages in thread
* [PATCH] net: sfp: Fix memory leak of hwmon_name on hwmon registration failure
@ 2026-08-05 4:36 Krishan Singh
2026-08-05 11:58 ` Andrew Lunn
0 siblings, 1 reply; 5+ messages in thread
From: Krishan Singh @ 2026-08-05 4:36 UTC (permalink / raw)
To: linux
Cc: andrew, hkallweit1, davem, edumazet, kuba, pabeni, netdev,
linux-kernel, Krishan Singh
hwmon_sanitize_name() allocates sfp->hwmon_name before
hwmon_device_register_with_info() is called. If the registration
fails, sfp->hwmon_dev is left as an error pointer while
sfp->hwmon_name remains allocated.
Later, when the SFP module is removed, sfp_hwmon_remove() is still
called. However, it frees sfp->hwmon_name only when
!IS_ERR_OR_NULL(sfp->hwmon_dev) is true. Since sfp->hwmon_dev is an
error pointer in the failure case, the cleanup block is skipped and
hwmon_name is leaked.
Fix this by cleaning up hwmon_name independently of hwmon_dev.
Continue to unregister the hwmon device only when hwmon_dev is valid,
but free hwmon_name whenever it is a valid allocated pointer.
Fixes: 3f118c449c8e ("net: sfp: use hwmon_sanitize_name()")
Suggested-by: Andrew Lunn <andrew@lunn.ch>
Signed-off-by: Krishan Singh <krishanmohan298@gmail.com>
---
drivers/net/phy/sfp.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/drivers/net/phy/sfp.c b/drivers/net/phy/sfp.c
index f52020673..bfa2b821f 100644
--- a/drivers/net/phy/sfp.c
+++ b/drivers/net/phy/sfp.c
@@ -1916,7 +1916,11 @@ static void sfp_hwmon_remove(struct sfp *sfp)
if (!IS_ERR_OR_NULL(sfp->hwmon_dev)) {
hwmon_device_unregister(sfp->hwmon_dev);
sfp->hwmon_dev = NULL;
+ }
+
+ if (!IS_ERR_OR_NULL(sfp->hwmon_name)) {
kfree(sfp->hwmon_name);
+ sfp->hwmon_name = NULL;
}
}
--
2.34.1
^ permalink raw reply related [flat|nested] 5+ messages in thread
* Re: [PATCH] net: sfp: Fix memory leak of hwmon_name on hwmon registration failure
2026-08-05 4:36 Krishan Singh
@ 2026-08-05 11:58 ` Andrew Lunn
2026-08-07 7:22 ` krishan mohan
0 siblings, 1 reply; 5+ messages in thread
From: Andrew Lunn @ 2026-08-05 11:58 UTC (permalink / raw)
To: Krishan Singh
Cc: linux, hkallweit1, davem, edumazet, kuba, pabeni, netdev,
linux-kernel
On Wed, Aug 05, 2026 at 10:06:43AM +0530, Krishan Singh wrote:
> hwmon_sanitize_name() allocates sfp->hwmon_name before
> hwmon_device_register_with_info() is called. If the registration
> fails, sfp->hwmon_dev is left as an error pointer while
> sfp->hwmon_name remains allocated.
>
> Later, when the SFP module is removed, sfp_hwmon_remove() is still
> called. However, it frees sfp->hwmon_name only when
> !IS_ERR_OR_NULL(sfp->hwmon_dev) is true. Since sfp->hwmon_dev is an
> error pointer in the failure case, the cleanup block is skipped and
> hwmon_name is leaked.
>
> Fix this by cleaning up hwmon_name independently of hwmon_dev.
> Continue to unregister the hwmon device only when hwmon_dev is valid,
> but free hwmon_name whenever it is a valid allocated pointer.
>
> Fixes: 3f118c449c8e ("net: sfp: use hwmon_sanitize_name()")
> Suggested-by: Andrew Lunn <andrew@lunn.ch>
> Signed-off-by: Krishan Singh <krishanmohan298@gmail.com>
> ---
Please read
https://docs.kernel.org/process/submitting-patches.html
There should be a version number in the Subject: line, and under the
--- a version history.
https://www.kernel.org/doc/html/latest/process/maintainer-netdev.html
For netdev, we want the tree to be indicated in the Subject: line. For
this patch i would suggest net-next.
Andrew
---
pw-bot: cr
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH] net: sfp: Fix memory leak of hwmon_name on hwmon registration failure
2026-08-05 11:58 ` Andrew Lunn
@ 2026-08-07 7:22 ` krishan mohan
2026-08-07 14:01 ` Andrew Lunn
0 siblings, 1 reply; 5+ messages in thread
From: krishan mohan @ 2026-08-07 7:22 UTC (permalink / raw)
To: Andrew Lunn
Cc: linux, hkallweit1, davem, edumazet, kuba, pabeni, netdev,
linux-kernel
[-- Attachment #1.1: Type: text/plain, Size: 2399 bytes --]
Hi All,
Please find v2 of this patch.
Changes since v1: - Move hwmon_name cleanup to sfp_hwmon_remove(). - Free
hwmon_name independently of hwmon_dev.
---
v2:
- Move hwmon_name cleanup to sfp_hwmon_remove().
- Free hwmon_name independently of hwmon_dev.
---
drivers/net/phy/sfp.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/drivers/net/phy/sfp.c b/drivers/net/phy/sfp.c
index f52020673..bfa2b821f 100644
--- a/drivers/net/phy/sfp.c
+++ b/drivers/net/phy/sfp.c
@@ -1916,7 +1916,11 @@ static void sfp_hwmon_remove(struct sfp *sfp)
if (!IS_ERR_OR_NULL(sfp->hwmon_dev)) {
hwmon_device_unregister(sfp->hwmon_dev);
sfp->hwmon_dev = NULL;
+ }
+
+ if (!IS_ERR_OR_NULL(sfp->hwmon_name)) {
kfree(sfp->hwmon_name);
+ sfp->hwmon_name = NULL;
}
}
--
Thanks&Regards
Krishan Mohan Singh
On Wed, Aug 5, 2026 at 5:28 PM Andrew Lunn <andrew@lunn.ch> wrote:
> On Wed, Aug 05, 2026 at 10:06:43AM +0530, Krishan Singh wrote:
> > hwmon_sanitize_name() allocates sfp->hwmon_name before
> > hwmon_device_register_with_info() is called. If the registration
> > fails, sfp->hwmon_dev is left as an error pointer while
> > sfp->hwmon_name remains allocated.
> >
> > Later, when the SFP module is removed, sfp_hwmon_remove() is still
> > called. However, it frees sfp->hwmon_name only when
> > !IS_ERR_OR_NULL(sfp->hwmon_dev) is true. Since sfp->hwmon_dev is an
> > error pointer in the failure case, the cleanup block is skipped and
> > hwmon_name is leaked.
> >
> > Fix this by cleaning up hwmon_name independently of hwmon_dev.
> > Continue to unregister the hwmon device only when hwmon_dev is valid,
> > but free hwmon_name whenever it is a valid allocated pointer.
> >
> > Fixes: 3f118c449c8e ("net: sfp: use hwmon_sanitize_name()")
> > Suggested-by: Andrew Lunn <andrew@lunn.ch>
> > Signed-off-by: Krishan Singh <krishanmohan298@gmail.com>
> > ---
>
> Please read
>
> https://docs.kernel.org/process/submitting-patches.html
>
> There should be a version number in the Subject: line, and under the
> --- a version history.
>
> https://www.kernel.org/doc/html/latest/process/maintainer-netdev.html
>
> For netdev, we want the tree to be indicated in the Subject: line. For
> this patch i would suggest net-next.
>
> Andrew
>
> ---
> pw-bot: cr
>
[-- Attachment #1.2: Type: text/html, Size: 3540 bytes --]
[-- Attachment #2: v2-0001-net-sfp-fix-hwmon_name-memory-leak-on-hwmon-regis.patch --]
[-- Type: text/x-patch, Size: 1571 bytes --]
From 9aab7f7e86228f708a9a968b756c83516b0ce817 Mon Sep 17 00:00:00 2001
From: Krishan Singh <krishanmohan298@gmail.com>
Date: Wed, 5 Aug 2026 10:04:47 +0530
Subject: [PATCH net-next v2] net: sfp: fix hwmon_name memory leak on hwmon
registration failure
hwmon_sanitize_name() allocates sfp->hwmon_name before
hwmon_device_register_with_info() is called. If the registration
fails, sfp->hwmon_dev is left pointing to an error while
sfp->hwmon_name remains allocated.
Later, when the SFP module is removed, sfp_hwmon_remove() only frees
hwmon_name when hwmon_dev is valid. As a result, hwmon_name is leaked
if hwmon_device_register_with_info() fails.
Free hwmon_name independently of hwmon_dev. Continue to unregister the
hwmon device only when hwmon_dev was successfully registered.
Fixes: 3f118c449c8e ("net: sfp: use hwmon_sanitize_name()")
Suggested-by: Andrew Lunn <andrew@lunn.ch>
Signed-off-by: Krishan Singh <krishanmohan298@gmail.com>
---
v2:
- Move hwmon_name cleanup to sfp_hwmon_remove().
- Free hwmon_name independently of hwmon_dev.
---
drivers/net/phy/sfp.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/drivers/net/phy/sfp.c b/drivers/net/phy/sfp.c
index f52020673..bfa2b821f 100644
--- a/drivers/net/phy/sfp.c
+++ b/drivers/net/phy/sfp.c
@@ -1916,7 +1916,11 @@ static void sfp_hwmon_remove(struct sfp *sfp)
if (!IS_ERR_OR_NULL(sfp->hwmon_dev)) {
hwmon_device_unregister(sfp->hwmon_dev);
sfp->hwmon_dev = NULL;
+ }
+
+ if (!IS_ERR_OR_NULL(sfp->hwmon_name)) {
kfree(sfp->hwmon_name);
+ sfp->hwmon_name = NULL;
}
}
--
2.34.1
^ permalink raw reply related [flat|nested] 5+ messages in thread
* Re: [PATCH] net: sfp: Fix memory leak of hwmon_name on hwmon registration failure
2026-08-07 7:22 ` krishan mohan
@ 2026-08-07 14:01 ` Andrew Lunn
0 siblings, 0 replies; 5+ messages in thread
From: Andrew Lunn @ 2026-08-07 14:01 UTC (permalink / raw)
To: krishan mohan
Cc: linux, hkallweit1, davem, edumazet, kuba, pabeni, netdev,
linux-kernel
On Fri, Aug 07, 2026 at 12:52:58PM +0530, krishan mohan wrote:
> Hi All,
>
> Please find v2 of this patch.
> Changes since v1: - Move hwmon_name cleanup to sfp_hwmon_remove(). - Free
> hwmon_name independently of hwmon_dev.
Please read:
https://docs.kernel.org/process/submitting-patches.html
and then submit a proper patch, following the process defined in this
document.
It is also important you start a new thread, otherwise the CI probably
does not work.
Andrew
---
pw-bot: cr
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2026-08-07 14:01 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-05 4:24 [PATCH] net: sfp: Fix memory leak of hwmon_name on hwmon registration failure Krishan Singh
-- strict thread matches above, loose matches on Subject: below --
2026-08-05 4:36 Krishan Singh
2026-08-05 11:58 ` Andrew Lunn
2026-08-07 7:22 ` krishan mohan
2026-08-07 14:01 ` Andrew Lunn
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox