---
id: CVE-2026-98239
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  net: lan743x: fix RX checksum use-after-free

  lan743x_rx_process_buffer() adds each non-first receive buffer to the
  head skb's frag_list
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  net: lan743x: fix RX checksum use-after-free

  lan743x_rx_process_buffer() adds each non-first receive buffer to the
  head skb's frag_list.  On the last descriptor, lan74…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a <
    0e52886c4324c9897c2c62f92be3dc8316cee67e
  - >-
    Linux >= cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a <
    a58024835c704419bb46d2a34e5223f65605f958
  - >-
    Linux >= cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a <
    6fe5c3a2503983abb431d93faeadfc7f5e6a7e33
  - >-
    Linux >= cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a <
    5c216bfa9fb7b36804485e67975e9c98055b31ef
  - >-
    Linux >= cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a <
    161a403c8625e152de03d1da22bbf9cda6dc9f9f
  - >-
    Linux >= cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a <
    a9ce4053dc945c5372dedba5017ee675b30dc0c5
  - Linux 6.1
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:18:11.803'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98239'
references:
  - url: 'https://git.kernel.org/stable/c/0e52886c4324c9897c2c62f92be3dc8316cee67e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/161a403c8625e152de03d1da22bbf9cda6dc9f9f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/5c216bfa9fb7b36804485e67975e9c98055b31ef'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/6fe5c3a2503983abb431d93faeadfc7f5e6a7e33'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/a58024835c704419bb46d2a34e5223f65605f958'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/a9ce4053dc945c5372dedba5017ee675b30dc0c5'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.433Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

net: lan743x: fix RX checksum use-after-free

lan743x_rx_process_buffer() adds each non-first receive buffer to the
head skb's frag_list.  On the last descriptor, lan743x_rx_trim_skb()
linearizes the head and frees the fragment skb metadata.

The checksum-success path then writes ip_summed through the local skb
pointer, which still points to the final fragment.  This causes a
use-after-free write when a packet spans more than one receive buffer.

Set ip_summed on the surviving head skb instead.  Multi-buffer receive
can occur after a live MTU increase because existing ring entries keep
their old buffer size until they are replenished.

A KUnit test invoking lan743x_rx_process_buffer() with a two-buffer
packet produced a one-byte KASAN use-after-free write before this change.
The same test passed after the change.  The driver object also builds
with W=1.  This was not tested on physical LAN743x hardware.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
