{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-98239","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:25:14.329Z","datePublished":"2026-10-06T08:45:10.611Z","dateUpdated":"2026-10-07T06:49:35.177Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-07T06:49:35.177Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: lan743x: fix RX checksum use-after-free\n\nlan743x_rx_process_buffer() adds each non-first receive buffer to the\nhead skb's frag_list.  On the last descriptor, lan743x_rx_trim_skb()\nlinearizes the head and frees the fragment skb metadata.\n\nThe checksum-success path then writes ip_summed through the local skb\npointer, which still points to the final fragment.  This causes a\nuse-after-free write when a packet spans more than one receive buffer.\n\nSet ip_summed on the surviving head skb instead.  Multi-buffer receive\ncan occur after a live MTU increase because existing ring entries keep\ntheir old buffer size until they are replenished.\n\nA KUnit test invoking lan743x_rx_process_buffer() with a two-buffer\npacket produced a one-byte KASAN use-after-free write before this change.\nThe same test passed after the change.  The driver object also builds\nwith W=1.  This was not tested on physical LAN743x hardware."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - The UAF write runs in lan743x_rx_process_buffer() (NAPI RX) while it handles an ordinary received Ethernet/IP frame from a remote sender. The sender's frame must be larger than the pre-change buffer size so the chip spreads it across several ring descriptors, which a routed jumbo-MTU path can deliver.\nAC:H - Buffers are sized mtu+ETH_HLEN+FCS+2 and the MAC caps frames at mtu+18 (MAC_RX_FSE_), so multi-buffer frames only occur after an admin raises the MTU on a live interface, while stale ring entries remain, or through the chip's occasional extra-buffer quirk. The remote attacker cannot produce either condition.\nPR:N - The trigger is a received frame with a valid checksum handled in the NAPI poll path, lan743x_rx_napi_poll -> lan743x_rx_process_buffer. The sender needs no authentication or credentials on the host.\nUI:N - Once the ring holds stale smaller buffers, no user on the victim needs to do anything; sending the oversized frame triggers the stale write. The admin's MTU change is already counted in AC:H.\nS:U - The freed sk_buff and the corrupted slab memory are inside the kernel itself; no VM, IOMMU or sandbox boundary is crossed.\nC:H - After skb_linearize() in lan743x_rx_trim_skb() frees the frag_list skb, its skbuff_head_cache slot can be reused by another skb. The stale write then hits a live object the attacker can steer with packet timing, which counts as a use-after-free per the scoring guidance.\nI:H - skb->ip_summed = CHECKSUM_UNNECESSARY is written into a freed sk_buff. If the slot has been reallocated, this corrupts another live skb and can make the stack accept forged or corrupted packets without checking their checksums. It is heap memory corruption.\nA:H - Writing into a freed and possibly reused sk_buff from the RX softirq can corrupt slab state and oops or panic the kernel; KASAN flagged the write in the author's KUnit reproducer."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/ethernet/microchip/lan743x_main.c"],"versions":[{"version":"cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a","lessThan":"0e52886c4324c9897c2c62f92be3dc8316cee67e","status":"affected","versionType":"git"},{"version":"cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a","lessThan":"a58024835c704419bb46d2a34e5223f65605f958","status":"affected","versionType":"git"},{"version":"cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a","lessThan":"6fe5c3a2503983abb431d93faeadfc7f5e6a7e33","status":"affected","versionType":"git"},{"version":"cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a","lessThan":"5c216bfa9fb7b36804485e67975e9c98055b31ef","status":"affected","versionType":"git"},{"version":"cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a","lessThan":"161a403c8625e152de03d1da22bbf9cda6dc9f9f","status":"affected","versionType":"git"},{"version":"cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a","lessThan":"a9ce4053dc945c5372dedba5017ee675b30dc0c5","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/ethernet/microchip/lan743x_main.c"],"versions":[{"version":"6.1","status":"affected"},{"version":"0","lessThan":"6.1","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.112","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.54","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.8","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc4","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1","versionEndExcluding":"6.12.112"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1","versionEndExcluding":"6.18.54"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1","versionEndExcluding":"7.2.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1","versionEndExcluding":"7.3-rc4"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/0e52886c4324c9897c2c62f92be3dc8316cee67e"},{"url":"https://git.kernel.org/stable/c/a58024835c704419bb46d2a34e5223f65605f958"},{"url":"https://git.kernel.org/stable/c/6fe5c3a2503983abb431d93faeadfc7f5e6a7e33"},{"url":"https://git.kernel.org/stable/c/5c216bfa9fb7b36804485e67975e9c98055b31ef"},{"url":"https://git.kernel.org/stable/c/161a403c8625e152de03d1da22bbf9cda6dc9f9f"},{"url":"https://git.kernel.org/stable/c/a9ce4053dc945c5372dedba5017ee675b30dc0c5"}],"title":"net: lan743x: fix RX checksum use-after-free","x_generator":{"engine":"bippy-1.2.0"}}}}