CVE-2026-98239

Source
https://cve.org/CVERecord?id=CVE-2026-98239
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98239.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98239
Downstream
Published
2026-10-06T08:45:10Z
Modified
2026-10-09T02:30:45Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
net: lan743x: fix RX checksum use-after-free
Details

In the Linux kernel, the following vulnerability has been resolved:

net: lan743x: fix RX checksum use-after-free

lan743x_rx_process_buffer() adds each non-first receive buffer to the head skb's frag_list. On the last descriptor, lan743x_rx_trim_skb() linearizes the head and frees the fragment skb metadata.

The checksum-success path then writes ip_summed through the local skb pointer, which still points to the final fragment. This causes a use-after-free write when a packet spans more than one receive buffer.

Set ip_summed on the surviving head skb instead. Multi-buffer receive can occur after a live MTU increase because existing ring entries keep their old buffer size until they are replenished.

A KUnit test invoking lan743x_rx_process_buffer() with a two-buffer packet produced a one-byte KASAN use-after-free write before this change. The same test passed after the change. The driver object also builds with W=1. This was not tested on physical LAN743x hardware.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98239.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a
Fixed
0e52886c4324c9897c2c62f92be3dc8316cee67e
Fixed
a58024835c704419bb46d2a34e5223f65605f958
Fixed
6fe5c3a2503983abb431d93faeadfc7f5e6a7e33
Fixed
5c216bfa9fb7b36804485e67975e9c98055b31ef
Fixed
161a403c8625e152de03d1da22bbf9cda6dc9f9f
Fixed
a9ce4053dc945c5372dedba5017ee675b30dc0c5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98239.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.1.0
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98239.json"