CVE-2026-53232

Source
https://cve.org/CVERecord?id=CVE-2026-53232
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53232.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-53232
Downstream
Related
Published
2026-06-25T08:39:30.527Z
Modified
2026-08-06T03:31:27.814067425Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
net: phy: clean the sfp upstream if phy probing fails
Details

In the Linux kernel, the following vulnerability has been resolved:

net: phy: clean the sfp upstream if phy probing fails

Sashiko reported that we don't call sfpbusdel_upstream() in the probe failure path, so let's add it, otherwise the sfp-bus is left with a dangling 'upstream' field, that may be used later on during SFP events.

This issue existed before the generic phylib sfp support, back when drivers were calling physfpprobe themselves.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53232.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
298e54fa810e027f1b0800d789eb862592721f08
Fixed
12fb84dc4dc8eb47ebe2b27f7de6255a4a205e1b
Fixed
9326b654f90a09eadeb796c82801a5609d57f0c8
Fixed
3a254779c169954fe23328a1db51f67be374f913
Fixed
0b27701ce93161d7bbf4b25fa20ca59963b0e20c
Fixed
48774e87bbaa0056819d4b52301e4692e50e3252

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53232.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
6.6.143
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.94
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.36
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.13

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53232.json"