CVE-2026-98239
In the Linux kernel, the following vulnerability has been resolved:
net: lan743x: fix RX checksum use-after-free
lan743x_rx_process_buffer() adds each non-first receive buffer to the head skb's frag_list. On the last descriptor, lan743x_rx_trim_skb() linearizes the head and frees the fragment skb metadata.
The checksum-success path then writes ip_summed through the local skb pointer, which still points to the final fragment. This causes a use-after-free write when a packet spans more than one receive buffer.
Set ip_summed on the surviving head skb instead. Multi-buffer receive can occur after a live MTU increase because existing ring entries keep their old buffer size until they are replenished.
Leer descripción completaMostrar menos
A KUnit test invoking lan743x_rx_process_buffer() with a two-buffer packet produced a one-byte KASAN use-after-free write before this change. The same test passed after the change. The driver object also builds with W=1. This was not tested on physical LAN743x hardware.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.18%
- Percentil entre todas las CVEs puntuadas: 7
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/0e52886c4324c9897c2c62f92be3dc8316cee67e
- https://git.kernel.org/stable/c/161a403c8625e152de03d1da22bbf9cda6dc9f9f
- https://git.kernel.org/stable/c/5c216bfa9fb7b36804485e67975e9c98055b31ef
- https://git.kernel.org/stable/c/6fe5c3a2503983abb431d93faeadfc7f5e6a7e33
- https://git.kernel.org/stable/c/a58024835c704419bb46d2a34e5223f65605f958
- https://git.kernel.org/stable/c/a9ce4053dc945c5372dedba5017ee675b30dc0c5
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-98239",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a",
"lessThan": "0e52886c4324c9897c2c62f92be3dc8316cee67e",
"versionType": "git"
},
{
"status": "affected",
"version": "cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a",
"lessThan": "a58024835c704419bb46d2a34e5223f65605f958",
"versionType": "git"
},
{
"status": "affected",
"version": "cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a",
"lessThan": "6fe5c3a2503983abb431d93faeadfc7f5e6a7e33",
"versionType": "git"
},
{
"status": "affected",
"version": "cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a",
"lessThan": "5c216bfa9fb7b36804485e67975e9c98055b31ef",
"versionType": "git"
},
{
"status": "affected",
"version": "cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a",
"lessThan": "161a403c8625e152de03d1da22bbf9cda6dc9f9f",
"versionType": "git"
},
{
"status": "affected",
"version": "cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a",
"lessThan": "a9ce4053dc945c5372dedba5017ee675b30dc0c5",
"versionType": "git"
}
],
"programFiles": [
"drivers/net/ethernet/microchip/lan743x_main.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.1"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.1",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.1.189",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.112",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.54",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.8",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc4",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/net/ethernet/microchip/lan743x_main.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-10-06T09:18:11.803",
"references": [
{
"url": "https://git.kernel.org/stable/c/0e52886c4324c9897c2c62f92be3dc8316cee67e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/161a403c8625e152de03d1da22bbf9cda6dc9f9f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/5c216bfa9fb7b36804485e67975e9c98055b31ef",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6fe5c3a2503983abb431d93faeadfc7f5e6a7e33",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a58024835c704419bb46d2a34e5223f65605f958",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a9ce4053dc945c5372dedba5017ee675b30dc0c5",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: lan743x: fix RX checksum use-after-free\n\nlan743x_rx_process_buffer() adds each non-first receive buffer to the\nhead skb's frag_list. On the last descriptor, lan743x_rx_trim_skb()\nlinearizes the head and frees the fragment skb metadata.\n\nThe checksum-success path then writes ip_summed through the local skb\npointer, which still points to the final fragment. This causes a\nuse-after-free write when a packet spans more than one receive buffer.\n\nSet ip_summed on the surviving head skb instead. Multi-buffer receive\ncan occur after a live MTU increase because existing ring entries keep\ntheir old buffer size until they are replenished.\n\nA KUnit test invoking lan743x_rx_process_buffer() with a two-buffer\npacket produced a one-byte KASAN use-after-free write before this change.\nThe same test passed after the change. The driver object also builds\nwith W=1. This was not tested on physical LAN743x hardware."
}
],
"lastModified": "2026-10-06T09:18:11.803",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}