NONE · 0

CVE-2026-90327

In the Linux kernel, the following vulnerability has been resolved: phonet: pep: do not write beyond optlen in getsockopt pep_getsockopt() clamps the reported length to the caller's buffer with min_...

Vulnerability Description

In the Linux kernel, the following vulnerability has been resolved: phonet: pep: do not write beyond optlen in getsockopt pep_getsockopt() clamps the reported length to the caller's buffer with min_t(), but then stores the value with put_user(val, (int __user *) optval), which always writes sizeof(int) bytes. A getsockopt() call with an optlen smaller than sizeof(int) thus reports the clamped length yet writes a full int, one to three bytes past the user buffer. Write the value with copy_to_user() bounded by len, so at most optlen bytes are copied, matching the length reported back to userspace.

References

FAQ

What is CVE-2026-90327?

CVE-2026-90327 is a documented vulnerability. In the Linux kernel, the following vulnerability has been resolved: phonet: pep: do not write beyond optlen in getsockopt pep_getsockopt() clamps the reported length to the caller's buffer with min_...

How severe is CVE-2026-90327?

CVSS scoring is not yet available for CVE-2026-90327. Check NVD for updates.

Is there a patch for CVE-2026-90327?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.