Executive brief
The Linux kernel's Phonet protocol stack contains a buffer overflow vulnerability in the PEP (Phonet Emulation Protocol) socket option handler. When an application queries socket options with a buffer smaller than expected, the kernel writes data beyond the buffer boundary, potentially corrupting adjacent memory. This could allow a local attacker to cause a kernel crash or potentially execute arbitrary code.
Technical details
The vulnerability is a stack buffer overflow in the pep_getsockopt() function within net/phonet/pep.c. The function clamps the reported option length to the caller's buffer size using min_t(), but then unconditionally writes a full sizeof(int) bytes using put_user(). A getsockopt() call with optlen smaller than sizeof(int) thus writes 1–3 bytes past the end of the user-supplied buffer. The fix replaces put_user() with copy_to_user() bounded by the clamped length. Attack vector is local; any unprivileged user can trigger this via the getsockopt() syscall on Phonet sockets. No authentication is required.
Affected products
- Linux Linux kernel all versions prior to the fix (introduced in commit 02a47617cdce)
Timeline
- 2026-09-17: disclosed: CVE-2026-90327 published
- 2026-09-14: patched: Fix committed by Jakub Kicinski to stable kernel branches