[PATCH] net: sfp: fix hwmon_name leak on hwmon registration failure

From: Krishan Singh

Date: Sat Aug 01 2026 - 03:00:34 EST


When hwmon_device_register_with_info() fails in sfp_hwmon_probe(),
the string allocated by hwmon_sanitize_name() is not freed, leaking
memory on repeated hotplug/probe attempts.

Also, sfp_hwmon_remove() only freed hwmon_name inside the
IS_ERR_OR_NULL(hwmon_dev) block, so a partial-init failure could
leave the name allocation behind.

Fix by freeing hwmon_name and clearing both pointers on registration
failure, and by freeing hwmon_name unconditionally in remove while
still only unregistering hwmon_dev when it is valid.

Fixes: 3f118c449c8e ("net: sfp: use hwmon_sanitize_name()")
Signed-off-by: Krishan Singh <krishanmohan298@xxxxxxxxx>
---
drivers/net/phy/sfp.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)

diff --git a/drivers/net/phy/sfp.c b/drivers/net/phy/sfp.c
index f52020673..f605fb399 100644
--- a/drivers/net/phy/sfp.c
+++ b/drivers/net/phy/sfp.c
@@ -1895,9 +1895,13 @@ static void sfp_hwmon_probe(struct work_struct *work)
sfp->hwmon_name, sfp,
&sfp_hwmon_chip_info,
NULL);
- if (IS_ERR(sfp->hwmon_dev))
+ if (IS_ERR(sfp->hwmon_dev)) {
dev_err(sfp->dev, "failed to register hwmon device: %ld\n",
PTR_ERR(sfp->hwmon_dev));
+ kfree(sfp->hwmon_name);
+ sfp->hwmon_name = NULL;
+ sfp->hwmon_dev = NULL;
+ }
}

static int sfp_hwmon_insert(struct sfp *sfp)
--
2.34.1