CVE-2026-53292: net: phonet: do not BUG_ON() in pn_socket_autobind() on failed bind

Published Jun 26, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

net: phonet: do not BUGON() in pnsocketautobind() on failed bind

syzbot reported a kernel BUG triggered from pnsocketsendmsg() via pnsocketautobind():

kernel BUG at net/phonet/socket.c:213! RIP: 0010:pnsocketautobind net/phonet/socket.c:213 [inline] RIP: 0010:pnsocketsendmsg+0x240/0x250 net/phonet/socket.c:421 Call Trace: socksendmsgnosec+0x112/0x150 net/socket.c:797 socksendmsg net/socket.c:812 [inline] syssendto+0x402/0x590 net/socket.c:2280 ...

pnsocketautobind() calls pnsocketbind() with port 0 and, on -EINVAL, assumes the socket was already bound and asserts that the port is non-zero:

err = pnsocketbind(sock, ..., sizeof(struct sockaddrpn)); if (err != -EINVAL) return err; BUGON(!pnport(pnsk(sock->sk)->sobject)); return 0; / socket was already bound /

However pnsocketbind() also returns -EINVAL when sk->skstate is not TCPCLOSE, even when the socket has never been bound and pnport() is still 0. In that case the BUGON() fires and panics the kernel from a user-triggerable path.

Treat the "bind returned -EINVAL but pnport() is still 0" case as a regular error and propagate -EINVAL to the caller instead of crashing. Existing callers already translate a non-zero return from pnsocketautobind() into -ENOBUFS/-EAGAIN, so returning -EINVAL here only changes behaviour from panic to a normal errno.

Affected Software

3 affected components
Linux Kernel
Linux Linux kernel>=2.6.28<7.0.10
Linux Linux kernel=7.1-rc1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    After applying the kernel fix, ensure phonet socket sendmsg paths do not trigger kernel BUGs in production (e.g., restrict/disable access to the vulnerable phonet userspace functionality until patched).

Event History

Jun 26, 2026
CVE Published
via MITRE·07:40 PM
Data Sourced
via MITRE·07:40 PM
Description
Data Sourced
via NVD·08:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jun 28, 2026
Data Sourced
via Microsoft·08:02 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What access does an attacker need to trigger this issue?

The CVSS vector indicates local access and low privileges are required, with no user interaction. The crash is reachable through a user-triggerable socket send path.

2

What is the impact of successful exploitation?

The affected code can hit a kernel BUG and panic the system, causing a denial of service. The provided CVSS vector indicates no confidentiality or integrity impact.

3

What condition causes the kernel panic?

The panic occurs when automatic binding receives -EINVAL from pn_socket_bind() because the socket state is not TCP_CLOSE, while the socket has never been bound and its Phonet port remains zero. The code incorrectly treats that result as proof that the socket was already bound.

4

How can I tell whether a system is affected?

Affected systems may show a kernel BUG at net/phonet/socket.c:213, with pn_socket_autobind and pn_socket_sendmsg in the call trace. The report does not provide affected or fixed kernel version ranges.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203