CVE-2026-53292: net: phonet: do not BUG_ON() in pn_socket_autobind() on failed bind
In the Linux kernel, the following vulnerability has been resolved:
net: phonet: do not BUGON() in pnsocketautobind() on failed bind
syzbot reported a kernel BUG triggered from pnsocketsendmsg() via pnsocketautobind():
kernel BUG at net/phonet/socket.c:213! RIP: 0010:pnsocketautobind net/phonet/socket.c:213 [inline] RIP: 0010:pnsocketsendmsg+0x240/0x250 net/phonet/socket.c:421 Call Trace: socksendmsgnosec+0x112/0x150 net/socket.c:797 socksendmsg net/socket.c:812 [inline] syssendto+0x402/0x590 net/socket.c:2280 ...
pnsocketautobind() calls pnsocketbind() with port 0 and, on -EINVAL, assumes the socket was already bound and asserts that the port is non-zero:
err = pnsocketbind(sock, ..., sizeof(struct sockaddrpn)); if (err != -EINVAL) return err; BUGON(!pnport(pnsk(sock->sk)->sobject)); return 0; / socket was already bound /
However pnsocketbind() also returns -EINVAL when sk->skstate is not TCPCLOSE, even when the socket has never been bound and pnport() is still 0. In that case the BUGON() fires and panics the kernel from a user-triggerable path.
Treat the "bind returned -EINVAL but pnport() is still 0" case as a regular error and propagate -EINVAL to the caller instead of crashing. Existing callers already translate a non-zero return from pnsocketautobind() into -ENOBUFS/-EAGAIN, so returning -EINVAL here only changes behaviour from panic to a normal errno.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
After applying the kernel fix, ensure phonet socket sendmsg paths do not trigger kernel BUGs in production (e.g., restrict/disable access to the vulnerable phonet userspace functionality until patched).
Event History
Frequently Asked Questions
What access does an attacker need to trigger this issue?
The CVSS vector indicates local access and low privileges are required, with no user interaction. The crash is reachable through a user-triggerable socket send path.
What is the impact of successful exploitation?
The affected code can hit a kernel BUG and panic the system, causing a denial of service. The provided CVSS vector indicates no confidentiality or integrity impact.
What condition causes the kernel panic?
The panic occurs when automatic binding receives -EINVAL from pn_socket_bind() because the socket state is not TCP_CLOSE, while the socket has never been bound and its Phonet port remains zero. The code incorrectly treats that result as proof that the socket was already bound.
How can I tell whether a system is affected?
Affected systems may show a kernel BUG at net/phonet/socket.c:213, with pn_socket_autobind and pn_socket_sendmsg in the call trace. The report does not provide affected or fixed kernel version ranges.