In the Linux kernel, the following vulnerability has been resolved:
firewire: net: fix use after free in fwnetfinishincoming_packet()
The netif_rx() function frees the skb so we can't dereference it to save the skb->len.