CVE-2026-98291
Bluetooth: btintel_pcie: fix off-by-one bounds check in RX submit
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel_pcie: fix off-by-one bounds check in RX submit btintel_pcie_submit_rx() used frbd_index > rxq->count to guard the FRBD array access, allowing frbd_index == rxq->count to pass through and index one element past the end of the array. Change the check to >= rxq->count so every out-of-range index is rejected. This issue was reported by Claude Mythos.
| Vendor | linux |
| Product | linux |
| Ecosystems | |
| Industries | Technology |
| Published | Oct 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for linux linux
Be the first to know when new unknown vulnerabilities affecting linux linux are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Linux / Linux
c2b636b3f788d10486a6691ad6dd3ec4c93bd78e < b5214d72bfdf8ef7744d0c8147e6ebb09b36b259 c2b636b3f788d10486a6691ad6dd3ec4c93bd78e < 18464860ce27af0dccd2fc72830610b85b518cff c2b636b3f788d10486a6691ad6dd3ec4c93bd78e < de4c3c72bcc6e8474f70c22427f94ca44bccd890 c2b636b3f788d10486a6691ad6dd3ec4c93bd78e < 2ea5a87a5a7ae58cb2662b8a7d06f209383e1765
Linux / Linux
6.10
References
git.kernel.org: https://git.kernel.org/stable/c/b5214d72bfdf8ef7744d0c8147e6ebb09b36b259 git.kernel.org: https://git.kernel.org/stable/c/18464860ce27af0dccd2fc72830610b85b518cff git.kernel.org: https://git.kernel.org/stable/c/de4c3c72bcc6e8474f70c22427f94ca44bccd890 git.kernel.org: https://git.kernel.org/stable/c/2ea5a87a5a7ae58cb2662b8a7d06f209383e1765