CVE-2026-53232
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/06/2026
Last modified:
16/07/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
net: phy: clean the sfp upstream if phy probing fails<br />
<br />
Sashiko reported that we don&#39;t call sfp_bus_del_upstream() in the probe<br />
failure path, so let&#39;s add it, otherwise the sfp-bus is left with a<br />
dangling &#39;upstream&#39; field, that may be used later on during SFP events.<br />
<br />
This issue existed before the generic phylib sfp support, back when<br />
drivers were calling phy_sfp_probe themselves.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.5 (including) | 7.1 (excluding) |
| cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc7:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/0b27701ce93161d7bbf4b25fa20ca59963b0e20c
- https://git.kernel.org/stable/c/12fb84dc4dc8eb47ebe2b27f7de6255a4a205e1b
- https://git.kernel.org/stable/c/3a254779c169954fe23328a1db51f67be374f913
- https://git.kernel.org/stable/c/48774e87bbaa0056819d4b52301e4692e50e3252
- https://git.kernel.org/stable/c/9326b654f90a09eadeb796c82801a5609d57f0c8



