Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-90327— phonet: pep: do not write beyond optlen in getsockopt

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux 内核中的以下漏洞已修复: 标题:phonet: pep: getsockopt 中不得在 optlen 之外写入 函数使用 将报告的长度限制在调用者的缓冲区大小内,但随后通过 存储该值,而 始终写入 字节。因此,当 调用中 小于 时,函数会报告一个被截断(clamped)的长度,但实际却写入了完整的 类型数据,导致超出用户缓冲区 1 到 3 个字节。 修复方式: 使用受 限制的 来写入值,从而最多只复制 字节的数量,使其与返回给用户空间(userspace)的长度一致。

AI Predicted 6.1 Difficulty: Moderate EPSS 0.21% · P10

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux 02a47617cdce440f60c71a51f3a93f9f5fcc5a7a< 6054fed6bad08b6d03973e8ffca7f0c9394d1c30 affected
02a47617cdce440f60c71a51f3a93f9f5fcc5a7a< eac733a0b6fe0a52d91f9f623425735ed50ac6c2 affected
02a47617cdce440f60c71a51f3a93f9f5fcc5a7a< 95e0ed2439dd1792eb454c68ae8d10f30ffe3bff affected
02a47617cdce440f60c71a51f3a93f9f5fcc5a7a< 056eea1a2068ad2fb7c3093c5f1095268f87d0c7 affected
02a47617cdce440f60c71a51f3a93f9f5fcc5a7a< 1bf499e438da80455e258049bce60ffb3a53f3fa affected
02a47617cdce440f60c71a51f3a93f9f5fcc5a7a< c4487e4d5309de587479ecc2f5173b49586f46f4 affected
02a47617cdce440f60c71a51f3a93f9f5fcc5a7a< f97022fefe6eb06ee18549d603420440f2959802 affected
02a47617cdce440f60c71a51f3a93f9f5fcc5a7a< 77e5eb0e192aec6710c03ca8144582fd2af36ca4 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-90327

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
phonet: pep: do not write beyond optlen in getsockopt
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: phonet: pep: do not write beyond optlen in getsockopt pep_getsockopt() clamps the reported length to the caller's buffer with min_t(), but then stores the value with put_user(val, (int __user *) optval), which always writes sizeof(int) bytes. A getsockopt() call with an optlen smaller than sizeof(int) thus reports the clamped length yet writes a full int, one to three bytes past the user buffer. Write the value with copy_to_user() bounded by len, so at most optlen bytes are copied, matching the length reported back to userspace.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 02a47617cdce440f60c71a51f3a93f9f5fcc5a7a ~ 6054fed6bad08b6d03973e8ffca7f0c9394d1c30 -
Linux Linux 2.6.28 -

II. Public POCs for CVE-2026-90327

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-90327

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-90327 (8)

Same Patch Batch · Linux · 2026-09-17 · 600 CVEs total

CVE-2026-92489 9.8 CRITICAL xfrm: Fix skb double-free in xfrm_dev_direct_output()
CVE-2026-90104 9.8 CRITICAL NFSv4.1: zero referring call lists before decoding
CVE-2026-90235 9.8 CRITICAL sunrpc: xprtsock: annotate shared socket callbacks with READ_ONCE/WRITE_ONCE
CVE-2026-90173 9.8 CRITICAL smb: smbdirect: free completion queues with ib_free_cq()
CVE-2026-90151 9.8 CRITICAL NFSv4: remove callback IDR entry on client allocation failure
CVE-2026-90110 9.4 CRITICAL inetpeer: randomize RB-tree node comparison using SipHash
CVE-2026-90413 9.1 CRITICAL IB/isert: reject login PDUs declaring more data than was received
CVE-2026-90414 9.1 CRITICAL IB/isert: reject PDUs declaring more data than was received
CVE-2026-90230 9.1 CRITICAL nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate()
CVE-2026-90256 8.8 HIGH Bluetooth: L2CAP: use proto_lock for l2cap_data to fix l2cap_disconn_ind
CVE-2026-90357 8.8 HIGH wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement
CVE-2026-90286 8.8 HIGH drm/amdgpu/gfx6: Use PFP on the compute queues too
CVE-2026-90381 8.8 HIGH wifi: mt76: fix handling channel context with different bands in mt76_switch_vif_chanctx()
CVE-2026-90380 8.8 HIGH wifi: mt76: mt792x: fix use-after-free in mt76_rx_poll_complete
CVE-2026-90329 8.8 HIGH HID: synchronize input before cleaning up a failed probe
CVE-2026-93042 8.8 HIGH dmaengine: dw-edma: Terminate all descriptors without callbacks
CVE-2026-90162 8.8 HIGH ksmbd: defer publishing granted locks to prevent UAF/double-free race
CVE-2026-90379 8.8 HIGH wifi: mt76: mt7921: Add PCIe AER handler support to prevent system crash
CVE-2026-90367 8.8 HIGH wifi: mt76: mt7996: hold dev->mt76.mutex while disabling tx worker in SER
CVE-2026-90371 8.8 HIGH wifi: mt76: fix RXDMAD_C buffer recycling race

Showing top 20 of 600 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-90327

No comments yet


Leave a comment