Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98239— net: lan743x: fix RX checksum use-after-free

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,以下漏洞已得到修复: net: lan743x:修复 RX 校验和使用后释放(use-after-free)问题 会将每个非首个接收缓冲区添加到头部 skb 的 中。在处理最后一个描述符时, 会将头部 skb 线性化,并释放 fragment(片段)skb 的元数据。 随后,在“校验和成功”路径中,代码通过局部 skb 指针写入 ,但该指针仍然指向最后的片段 skb。当数据包跨越多个接收缓冲区时,这会导致使用后释放(use-after-free)写入错误。 修复方法是将 设置到仍然存活的头部

CVSS 8.1 · High EPSS 0.47% · P39

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 14

VendorProduct Version RangeStatus
Linux Linux cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a< 0e52886c4324c9897c2c62f92be3dc8316cee67e affected
cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a< a58024835c704419bb46d2a34e5223f65605f958 affected
cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a< 6fe5c3a2503983abb431d93faeadfc7f5e6a7e33 affected
cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a< 5c216bfa9fb7b36804485e67975e9c98055b31ef affected
cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a< 161a403c8625e152de03d1da22bbf9cda6dc9f9f affected
cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a< a9ce4053dc945c5372dedba5017ee675b30dc0c5 affected
6.1 affected
< 6.1 unaffected
… +6 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98239

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
net: lan743x: fix RX checksum use-after-free
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: net: lan743x: fix RX checksum use-after-free lan743x_rx_process_buffer() adds each non-first receive buffer to the head skb's frag_list. On the last descriptor, lan743x_rx_trim_skb() linearizes the head and frees the fragment skb metadata. The checksum-success path then writes ip_summed through the local skb pointer, which still points to the final fragment. This causes a use-after-free write when a packet spans more than one receive buffer. Set ip_summed on the surviving head skb instead. Multi-buffer receive can occur after a live MTU increase because existing ring entries keep their old buffer size until they are replenished. A KUnit test invoking lan743x_rx_process_buffer() with a two-buffer packet produced a one-byte KASAN use-after-free write before this change. The same test passed after the change. The driver object also builds with W=1. This was not tested on physical LAN743x hardware.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a ~ 0e52886c4324c9897c2c62f92be3dc8316cee67e -
Linux Linux 6.1 -

II. Public POCs for CVE-2026-98239

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98239

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98239 (6)

Same Patch Batch · Linux · 2026-10-06 · 208 CVEs total

CVE-2026-98323 9.8 CRITICAL RDMA/siw: Bound fragmented header copies by the remaining length
CVE-2026-98365 9.8 CRITICAL RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access
CVE-2026-98282 8.8 HIGH powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
CVE-2026-98283 8.8 HIGH KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()
CVE-2026-98339 8.8 HIGH wifi: cfg80211: don't filter by BSS type when removing stale entries
CVE-2026-98171 8.8 HIGH smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
CVE-2026-98261 8.1 HIGH cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
CVE-2026-98357 8.1 HIGH IB/isert: wait for deferred control PDU completions before releasing the connection
CVE-2026-98341 7.8 HIGH wifi: cfg80211: don't free driver-owned scan requests
CVE-2026-98324 7.8 HIGH dmaengine: pxa: fix double counting of the hw descriptors
CVE-2026-98320 7.8 HIGH netfilter: flowtable: hold reference on ct until flow is released
CVE-2026-98228 7.8 HIGH mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ
CVE-2026-98229 7.8 HIGH xfrm: save input state data before secpath resets
CVE-2026-98318 7.8 HIGH smb: client: validate absolute native symlink targets before NT fixups
CVE-2026-98315 7.8 HIGH ntfs: protect runlist updates with the runlist lock
CVE-2026-98311 7.8 HIGH wifi: virt_wifi: don't transfer operstate before register
CVE-2026-98276 7.8 HIGH net: lock the socket in sock_gettstamp()
CVE-2026-98258 7.8 HIGH posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list
CVE-2026-98260 7.8 HIGH exec: Cleanup POSIX timers right after de_thread()
CVE-2026-98256 7.8 HIGH signal: Prevent exec() race

Showing top 20 of 208 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-98239

No comments yet


Leave a comment