๐Ÿ” CVE Alert

CVE-2026-97976

UNKNOWN 0.0

Bluetooth: btintel_pcie: validate packet_len before skb_put_data

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel_pcie: validate packet_len before skb_put_data btintel_pcie_submit_rx_work() reads packet_len from rfh_hdr without checking if it exceeds the RX buffer size. An oversized packet_len can lead to an out-of-bounds read in skb_put_data(). Validate packet_len to ensure it is non-zero and does not exceed BTINTEL_PCIE_BUFFER_SIZE - sizeof(*rfh_hdr), logging an error when invalid. This issue was reported by Claude Mythos. It can be simulated either by using customized firmware configured to return an invalid packet_len or by modifying rfh_hdr->packet_len in the driver before calling btintel_pcie_submit_rx_work().

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
c2b636b3f788d10486a6691ad6dd3ec4c93bd78e < ab0159b1f7214ce9bad9862751e4553e635a21b1 c2b636b3f788d10486a6691ad6dd3ec4c93bd78e < 73a50c636425cb9f7ab647b5a97bd14dd5610076 c2b636b3f788d10486a6691ad6dd3ec4c93bd78e < 46884c0f92708f1d218fc94d88800227a19b52f8 c2b636b3f788d10486a6691ad6dd3ec4c93bd78e < 6436e1b5331b1aebf905c13e0880a37032719b75
Linux / Linux
6.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/ab0159b1f7214ce9bad9862751e4553e635a21b1 git.kernel.org: https://git.kernel.org/stable/c/73a50c636425cb9f7ab647b5a97bd14dd5610076 git.kernel.org: https://git.kernel.org/stable/c/46884c0f92708f1d218fc94d88800227a19b52f8 git.kernel.org: https://git.kernel.org/stable/c/6436e1b5331b1aebf905c13e0880a37032719b75