CVE-2026-98296 PUBLISHED

Bluetooth: btintel_pcie: validate TX skb length in send_sync

Assigner: Linux
Reserved: 25.09.2026 Published: 06.10.2026 Updated: 06.10.2026

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: btintel_pcie: validate TX skb length in send_sync

btintel_pcie_prepare_tx() copies skb->len bytes into a fixed BTINTEL_PCIE_BUFFER_SIZE (4096) DMA slot via an unchecked memcpy. Oversized packets are currently rejected only in btintel_pcie_send_frame(); any future caller of btintel_pcie_send_sync() would silently overflow the DMA buffer.

Add the bounds check in btintel_pcie_send_sync() itself, right before skb_push() and the DMA copy.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 6e65a09f927566f257322358d429b267548473eb to 84f353256e170dc4865d45007d1bc446ed566da7 (excl.)
  • affected from 6e65a09f927566f257322358d429b267548473eb to c298a61e18029401486c40298a50fbeea7e7b663 (excl.)
  • affected from 6e65a09f927566f257322358d429b267548473eb to 4b837ebd0ea21ae5cc26f02dc042edc6fe7b46b9 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.10 is affected
  • unaffected from 0 to 6.10 (excl.)
  • unaffected from 6.18.54 to 6.18.* (incl.)
  • unaffected from 7.2.8 to 7.2.* (incl.)
  • unaffected from 7.3-rc4 to * (incl.)

References