{"id":"CVE-2026-98239","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: lan743x: fix RX checksum use-after-free\n\nlan743x_rx_process_buffer() adds each non-first receive buffer to the\nhead skb's frag_list","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: lan743x: fix RX checksum use-after-free\n\nlan743x_rx_process_buffer() adds each non-first receive buffer to the\nhead skb's frag_list.  On the last descriptor, lan74…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a < 0e52886c4324c9897c2c62f92be3dc8316cee67e","Linux >= cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a < a58024835c704419bb46d2a34e5223f65605f958","Linux >= cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a < 6fe5c3a2503983abb431d93faeadfc7f5e6a7e33","Linux >= cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a < 5c216bfa9fb7b36804485e67975e9c98055b31ef","Linux >= cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a < 161a403c8625e152de03d1da22bbf9cda6dc9f9f","Linux >= cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a < a9ce4053dc945c5372dedba5017ee675b30dc0c5","Linux 6.1"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:18:11.803","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98239","references":[{"url":"https://git.kernel.org/stable/c/0e52886c4324c9897c2c62f92be3dc8316cee67e","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/161a403c8625e152de03d1da22bbf9cda6dc9f9f","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5c216bfa9fb7b36804485e67975e9c98055b31ef","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6fe5c3a2503983abb431d93faeadfc7f5e6a7e33","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a58024835c704419bb46d2a34e5223f65605f958","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a9ce4053dc945c5372dedba5017ee675b30dc0c5","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T08:50:17.433Z","slug":"CVE-2026-98239","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet: lan743x: fix RX checksum use-after-free\n\nlan743x_rx_process_buffer() adds each non-first receive buffer to the\nhead skb's frag_list.  On the last descriptor, lan743x_rx_trim_skb()\nlinearizes the head and frees the fragment skb metadata.\n\nThe checksum-success path then writes ip_summed through the local skb\npointer, which still points to the final fragment.  This causes a\nuse-after-free write when a packet spans more than one receive buffer.\n\nSet ip_summed on the surviving head skb instead.  Multi-buffer receive\ncan occur after a live MTU increase because existing ring entries keep\ntheir old buffer size until they are replenished.\n\nA KUnit test invoking lan743x_rx_process_buffer() with a two-buffer\npacket produced a one-byte KASAN use-after-free write before this change.\nThe same test passed after the change.  The driver object also builds\nwith W=1.  This was not tested on physical LAN743x hardware.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}