Executive brief
The Linux kernel's SFP (Small Form-factor Pluggable) networking driver fails to properly free memory when removing copper or RollBall SFP modules. This memory leak occurs in the I2C MDIO bus cleanup routine, causing allocated bus structures to remain in memory indefinitely when modules are hot-removed. Over time, repeated module insertions and removals can accumulate these leaked memory structures, potentially degrading system stability.
Technical details
The vulnerability is a memory leak (CWE-401) in the SFP driver's I2C MDIO bus handling. The sfp_i2c_mdiobus_create() function allocates an mii_bus structure via mdio_i2c_alloc() (non-devm allocation), but the corresponding sfp_i2c_mdiobus_destroy() function only calls mdiobus_unregister() and clears the pointer without calling mdiobus_free(). This leaves the allocated structure orphaned. The leak is triggered when copper/RollBall SFP modules are removed via the module hot-removal path (sfp_sm_main() → sfp_i2c_mdiobus_destroy()), though not during driver unbind. The fix adds a single mdiobus_free() call in sfp_i2c_mdiobus_destroy() to properly deallocate the bus structure.
Affected products
- Linux Linux kernel affected versions vary by stable branch (patch applied across linux-4.19.y through linux-7.2.y and master)
Timeline
- 2026-08-15: disclosed
- 2026-06-27: patched: Original fix commit upstream