๐Ÿ” CVE Alert

CVE-2026-98296

UNKNOWN 0.0

Bluetooth: btintel_pcie: validate TX skb length in send_sync

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel_pcie: validate TX skb length in send_sync btintel_pcie_prepare_tx() copies skb->len bytes into a fixed BTINTEL_PCIE_BUFFER_SIZE (4096) DMA slot via an unchecked memcpy. Oversized packets are currently rejected only in btintel_pcie_send_frame(); any future caller of btintel_pcie_send_sync() would silently overflow the DMA buffer. Add the bounds check in btintel_pcie_send_sync() itself, right before skb_push() and the DMA copy.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
6e65a09f927566f257322358d429b267548473eb < 84f353256e170dc4865d45007d1bc446ed566da7 6e65a09f927566f257322358d429b267548473eb < c298a61e18029401486c40298a50fbeea7e7b663 6e65a09f927566f257322358d429b267548473eb < 4b837ebd0ea21ae5cc26f02dc042edc6fe7b46b9
Linux / Linux
6.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/84f353256e170dc4865d45007d1bc446ed566da7 git.kernel.org: https://git.kernel.org/stable/c/c298a61e18029401486c40298a50fbeea7e7b663 git.kernel.org: https://git.kernel.org/stable/c/4b837ebd0ea21ae5cc26f02dc042edc6fe7b46b9