Impact
This vulnerability in the Linux kernel’s phonet pep_getsockopt implementation causes it to write a full 4-byte integer to user space even when the caller’s optlen is smaller, resulting in an out‑of‑bounds write. The reported length is clamped to the caller’s buffer size, but the write still exceeds that boundary by one to three bytes, potentially corrupting adjacent user memory. Such corruption can lead to a crash or, in certain edge cases, an attacker‑controlled write into user space that can be used for privilege escalation or code execution.
Affected Systems
All Linux kernel releases that include the phonet and pep driver components and have not yet applied the commit that limits writes to optlen. The fix was applied in the stable tree; therefore any kernel version before that commit, regardless of distribution, is affected.
Risk and Exploitability
The vulnerability has a low EPSS (<1%) and is not listed as a known exploited vulnerability in CISA’s KEV catalog, indicating a modest probability of real‑world exploitation. The threat is local: a process that calls getsockopt() on a socket using phonet/pep can trigger the out‑of‑bounds write. No special privileges are required beyond the ability to use the socket API, so any local user can exploit it. Because the impact is a memory overflow into user space, a crash is the most likely outcome, but an attacker may also craft input that leads to malicious code execution if the overwritten memory is used later by the process.
OpenCVE Enrichment
Debian DLA
Debian DSA