CVE-2026-90327: vulnerability in Linux
phonet: pep: do not write beyond optlen in getsockopt
Published
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.2%
exploitation probability
0.2%top 90% of all CVEs
observed exploitation
nono source reports it
In the Linux kernel, the following vulnerability has been resolved:
phonet: pep: do not write beyond optlen in getsockopt
pep_getsockopt() clamps the reported length to the caller's buffer with
min_t(), but then stores the value with put_user(val, (int __user *)
optval), which always writes sizeof(int) bytes. A getsockopt() call with
an optlen smaller than sizeof(int) thus reports the clamped length yet
writes a full int, one to three bytes past the user buffer.
Write the value with copy_to_user() bounded by len, so at most optlen
bytes are copied, matching the length reported back to userspace.
Affected products
Linux · LinuxRelated CVEs — Linux
In the same product, most dangerous first.
CVE-2024-53197HIGHALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devicesEPSS 4.1%KEVCVE-2026-31431HIGHcrypto: algif_aead - Revert to operating out-of-placeEPSS 3.4%KEVCVE-2024-53104HIGHmedia: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_formatEPSS 3.4%KEVCVE-2025-39682CRITICALtls: fix handling of zero-length records on the rx_listEPSS 2.9%KEVCVE-2024-36971HIGHnet: fix __dst_negative_advice() raceEPSS 2.7%KEVCVE-2024-53150HIGHALSA: usb-audio: Fix out of bounds reads when finding clock sourcesEPSS 1.4%KEV
References
https://git.kernel.org/stable/c/056eea1a2068ad2fb7c3093c5f1095268f87d0c7https://git.kernel.org/stable/c/1bf499e438da80455e258049bce60ffb3a53f3fahttps://git.kernel.org/stable/c/6054fed6bad08b6d03973e8ffca7f0c9394d1c30https://git.kernel.org/stable/c/77e5eb0e192aec6710c03ca8144582fd2af36ca4https://git.kernel.org/stable/c/95e0ed2439dd1792eb454c68ae8d10f30ffe3bffhttps://git.kernel.org/stable/c/c4487e4d5309de587479ecc2f5173b49586f46f4https://git.kernel.org/stable/c/eac733a0b6fe0a52d91f9f623425735ed50ac6c2https://git.kernel.org/stable/c/f97022fefe6eb06ee18549d603420440f2959802