Re: [PATCH net-next v3 4/7] phonet: pep: do not write beyond optlen in getsockopt
From: Stanislav Fomichev
Date: Mon Jul 27 2026 - 11:42:24 EST
On 07/27, Breno Leitao wrote:
> pep_getsockopt() clamps the reported length to the caller's buffer with
> min_t(), but then stores the value with put_user(val, (int __user *)
> optval), which always writes sizeof(int) bytes. A getsockopt() call with
> an optlen smaller than sizeof(int) thus reports the clamped length yet
> writes a full int, one to three bytes past the user buffer.
>
> Write the value with copy_to_user() bounded by len, so at most optlen
> bytes are copied, matching the length reported back to userspace.
>
> Fixes: 02a47617cdce ("Phonet: implement GPRS virtual interface over PEP socket")
> Acked-by: Rémi Denis-Courmont <remi@xxxxxxxxxx>
> Reviewed-by: Joe Damato <joe@xxxxxxx>
> Signed-off-by: Breno Leitao <leitao@xxxxxxxxxx>
Acked-by: Stanislav Fomichev <sdf@xxxxxxxxxxx>