Description
In the Linux kernel, the following vulnerability has been resolved:

phonet: pep: do not write beyond optlen in getsockopt

pep_getsockopt() clamps the reported length to the caller's buffer with
min_t(), but then stores the value with put_user(val, (int __user *)
optval), which always writes sizeof(int) bytes. A getsockopt() call with
an optlen smaller than sizeof(int) thus reports the clamped length yet
writes a full int, one to three bytes past the user buffer.

Write the value with copy_to_user() bounded by len, so at most optlen
bytes are copied, matching the length reported back to userspace.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-bounds write leading to possible user buffer corruption
Action: Update kernel
AI Analysis

Impact

This vulnerability in the Linux kernel’s phonet pep_getsockopt implementation causes it to write a full 4-byte integer to user space even when the caller’s optlen is smaller, resulting in an out‑of‑bounds write. The reported length is clamped to the caller’s buffer size, but the write still exceeds that boundary by one to three bytes, potentially corrupting adjacent user memory. Such corruption can lead to a crash or, in certain edge cases, an attacker‑controlled write into user space that can be used for privilege escalation or code execution.

Affected Systems

All Linux kernel releases that include the phonet and pep driver components and have not yet applied the commit that limits writes to optlen. The fix was applied in the stable tree; therefore any kernel version before that commit, regardless of distribution, is affected.

Risk and Exploitability

The vulnerability has a low EPSS (<1%) and is not listed as a known exploited vulnerability in CISA’s KEV catalog, indicating a modest probability of real‑world exploitation. The threat is local: a process that calls getsockopt() on a socket using phonet/pep can trigger the out‑of‑bounds write. No special privileges are required beyond the ability to use the socket API, so any local user can exploit it. Because the impact is a memory overflow into user space, a crash is the most likely outcome, but an attacker may also craft input that leads to malicious code execution if the overwritten memory is used later by the process.

Generated by OpenCVE AI on September 19, 2026 at 04:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that limits writes to optlen in pep_getsockopt by updating to a kernel version that contains the fix.
  • If patching cannot be performed immediately, disable or remove the phonet/pep drivers from the kernel and avoid invoking getsockopt() on sockets that use these drivers until a fix is available.
  • Review any custom kernel modules that interact with phonet/pep and add bounds checking to ensure user buffers are not written beyond their declared size, following the fixed approach of using copy_to_user() with a length limit.

Generated by OpenCVE AI on September 19, 2026 at 04:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: phonet: pep: do not write beyond optlen in getsockopt pep_getsockopt() clamps the reported length to the caller's buffer with min_t(), but then stores the value with put_user(val, (int __user *) optval), which always writes sizeof(int) bytes. A getsockopt() call with an optlen smaller than sizeof(int) thus reports the clamped length yet writes a full int, one to three bytes past the user buffer. Write the value with copy_to_user() bounded by len, so at most optlen bytes are copied, matching the length reported back to userspace.
Title phonet: pep: do not write beyond optlen in getsockopt
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:42.017Z

Reserved: 2026-09-11T19:38:34.802Z

Link: CVE-2026-90327

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:30.800

Modified: 2026-09-17T17:17:30.800

Link: CVE-2026-90327

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T05:00:09Z

Weaknesses