CVE-2026-98239: net: lan743x: fix RX checksum use-after-free

Published Oct 6, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

net: lan743x: fix RX checksum use-after-free

lan743xrxprocessbuffer() adds each non-first receive buffer to the head skb's fraglist. On the last descriptor, lan743xrxtrimskb() linearizes the head and frees the fragment skb metadata.

The checksum-success path then writes ipsummed through the local skb pointer, which still points to the final fragment. This causes a use-after-free write when a packet spans more than one receive buffer.

Set ipsummed on the surviving head skb instead. Multi-buffer receive can occur after a live MTU increase because existing ring entries keep their old buffer size until they are replenished.

A KUnit test invoking lan743xrxprocessbuffer() with a two-buffer packet produced a one-byte KASAN use-after-free write before this change. The same test passed after the change. The driver object also builds with W=1. This was not tested on physical LAN743x hardware.

Affected Software

1 affected component
Linux Linux kernel

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    In the LAN743x RX path, update lan743x_rx_trim_skb() on the last descriptor to set ip_summed on the surviving head skb instead of the local skb pointer that still points to the freed final fragment.

Event History

Oct 6, 2026
CVE Published
via MITRE·08:45 AM
Data Sourced
via MITRE·08:45 AM
DescriptionSeverity
Data Sourced
via NVD·09:18 AM
DescriptionSeverity
Oct 7, 2026
Data Sourced
via Microsoft·08:47 AM
DescriptionSeverityWeakness
Sep 7, 58736
Event
via FIRST·02:40 AM

Frequently Asked Questions

1

What level of access would an attacker need to attempt exploitation?

The CVSS vector indicates network reachability, with no privileges or user interaction required. Exploitation complexity is rated high.

2

Which deployments are most likely to be exposed?

Systems running the Linux LAN743x network driver are relevant. The vulnerable path is reached when received traffic spans multiple receive buffers, a condition noted after a live MTU increase while ring entries still use the prior buffer size.

3

Was the fix validated on physical hardware?

No. The change was validated with a KUnit two-buffer-packet test and built with W=1, but it was not tested on physical LAN743x hardware.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203