In the Linux kernel, the following vulnerability has been resolved:
phonet: pep: do not write beyond optlen in getsockopt
pep_getsockopt() clamps the reported length to the caller's buffer with min_t(), but then stores the value with put_user(val, (int __user *) optval), which always writes sizeof(int) bytes. A getsockopt() call with an optlen smaller than sizeof(int) thus reports the clamped length yet writes a full int, one to three bytes past the user buffer.
Write the value with copy_to_user() bounded by len, so at most optlen bytes are copied, matching the length reported back to userspace.
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90327.json"
}