Junglewise Threat Intelligence

CVE-2026-90327: Linux kernel Phonet PEP buffer overflow in getsockopt

CVE-2026-90327 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's Phonet protocol stack contains a buffer overflow vulnerability in the PEP (Phonet Emulation Protocol) socket option handler. When an application queries socket options with a buffer smaller than expected, the kernel writes data beyond the buffer boundary, potentially corrupting adjacent memory. This could allow a local attacker to cause a kernel crash or potentially execute arbitrary code.

Technical details

The vulnerability is a stack buffer overflow in the pep_getsockopt() function within net/phonet/pep.c. The function clamps the reported option length to the caller's buffer size using min_t(), but then unconditionally writes a full sizeof(int) bytes using put_user(). A getsockopt() call with optlen smaller than sizeof(int) thus writes 1–3 bytes past the end of the user-supplied buffer. The fix replaces put_user() with copy_to_user() bounded by the clamped length. Attack vector is local; any unprivileged user can trigger this via the getsockopt() syscall on Phonet sockets. No authentication is required.

Affected products

  • Linux Linux kernel all versions prior to the fix (introduced in commit 02a47617cdce)

Timeline

  • 2026-09-17: disclosed: CVE-2026-90327 published
  • 2026-09-14: patched: Fix committed by Jakub Kicinski to stable kernel branches

References

Related threats