CVE-2026-98239
Received Received - Intake

Use-After-Free in Linux Kernel lan743x Driver

Vulnerability report for CVE-2026-98239, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: net: lan743x: fix RX checksum use-after-free lan743x_rx_process_buffer() adds each non-first receive buffer to the head skb's frag_list. On the last descriptor, lan743x_rx_trim_skb() linearizes the head and frees the fragment skb metadata. The checksum-success path then writes ip_summed through the local skb pointer, which still points to the final fragment. This causes a use-after-free write when a packet spans more than one receive buffer. Set ip_summed on the surviving head skb instead. Multi-buffer receive can occur after a live MTU increase because existing ring entries keep their old buffer size until they are replenished. A KUnit test invoking lan743x_rx_process_buffer() with a two-buffer packet produced a one-byte KASAN use-after-free write before this change. The same test passed after the change. The driver object also builds with W=1. This was not tested on physical LAN743x hardware.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
Linux Linux cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a
Linux Linux cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a
Linux Linux cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a
Linux Linux cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a
Linux Linux cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a
Linux Linux cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a
Linux Linux 6.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a use-after-free vulnerability in the Linux kernel's lan743x network driver. It occurs when processing received network packets that span multiple buffers. The driver incorrectly sets checksum flags on a freed fragment buffer instead of the surviving head buffer, causing a write-after-free condition.

Detection Guidance

This vulnerability is specific to the Linux kernel's lan743x driver and may not have direct detection commands. Monitor kernel logs for KASAN or slab errors related to network buffers. Check for crashes or corruption during network operations involving the lan743x driver.

Impact Analysis

This vulnerability could allow an attacker to cause system instability or execute arbitrary code with kernel privileges by sending specially crafted network packets. Systems using the affected lan743x driver may experience crashes or security breaches.

Mitigation Strategies

Update the Linux kernel to a patched version that includes the fix for CVE-2026-98239. Avoid increasing the MTU while the system is under heavy network load to reduce the risk of multi-buffer packets.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98239. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart