8.1

CVE-2026-98239

net: lan743x: fix RX checksum use-after-free

In the Linux kernel, the following vulnerability has been resolved:

net: lan743x: fix RX checksum use-after-free

lan743x_rx_process_buffer() adds each non-first receive buffer to the
head skb's frag_list.  On the last descriptor, lan743x_rx_trim_skb()
linearizes the head and frees the fragment skb metadata.

The checksum-success path then writes ip_summed through the local skb
pointer, which still points to the final fragment.  This causes a
use-after-free write when a packet spans more than one receive buffer.

Set ip_summed on the surviving head skb instead.  Multi-buffer receive
can occur after a live MTU increase because existing ring entries keep
their old buffer size until they are replenished.

A KUnit test invoking lan743x_rx_process_buffer() with a two-buffer
packet produced a one-byte KASAN use-after-free write before this change.
The same test passed after the change.  The driver object also builds
with W=1.  This was not tested on physical LAN743x hardware.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a
Version < 0e52886c4324c9897c2c62f92be3dc8316cee67e
Status affected
Version cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a
Version < a58024835c704419bb46d2a34e5223f65605f958
Status affected
Version cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a
Version < 6fe5c3a2503983abb431d93faeadfc7f5e6a7e33
Status affected
Version cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a
Version < 5c216bfa9fb7b36804485e67975e9c98055b31ef
Status affected
Version cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a
Version < 161a403c8625e152de03d1da22bbf9cda6dc9f9f
Status affected
Version cd6910501cfd9a3bdff2f5fc33c9f3cf165ca54a
Version < a9ce4053dc945c5372dedba5017ee675b30dc0c5
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.1
Status affected
Version 0
Version < 6.1
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.54
Status unaffected
Version <= 7.2.*
Version 7.2.8
Status unaffected
Version <= *
Version 7.3-rc4
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.47% 0.389
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/0e52886c4324c9897c2c62f92be3dc8316cee67e
https://git.kernel.org/stable/c/a58024835c704419bb46d2a34e5223f65605f958
https://git.kernel.org/stable/c/6fe5c3a2503983abb431d93faeadfc7f5e6a7e33
https://git.kernel.org/stable/c/5c216bfa9fb7b36804485e67975e9c98055b31ef
https://git.kernel.org/stable/c/161a403c8625e152de03d1da22bbf9cda6dc9f9f
https://git.kernel.org/stable/c/a9ce4053dc945c5372dedba5017ee675b30dc0c5