-

CVE-2026-97976

Bluetooth: btintel_pcie: validate packet_len before skb_put_data

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: btintel_pcie: validate packet_len before skb_put_data

btintel_pcie_submit_rx_work() reads packet_len from rfh_hdr without
checking if it exceeds the RX buffer size. An oversized packet_len
can lead to an out-of-bounds read in skb_put_data().

Validate packet_len to ensure it is non-zero and does not exceed
BTINTEL_PCIE_BUFFER_SIZE - sizeof(*rfh_hdr), logging an error when
invalid.

This issue was reported by Claude Mythos. It can be simulated either by
using customized firmware configured to return an invalid packet_len or
by modifying rfh_hdr->packet_len in the driver before calling
btintel_pcie_submit_rx_work().
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version c2b636b3f788d10486a6691ad6dd3ec4c93bd78e
Version < ab0159b1f7214ce9bad9862751e4553e635a21b1
Status affected
Version c2b636b3f788d10486a6691ad6dd3ec4c93bd78e
Version < 73a50c636425cb9f7ab647b5a97bd14dd5610076
Status affected
Version c2b636b3f788d10486a6691ad6dd3ec4c93bd78e
Version < 46884c0f92708f1d218fc94d88800227a19b52f8
Status affected
Version c2b636b3f788d10486a6691ad6dd3ec4c93bd78e
Version < 6436e1b5331b1aebf905c13e0880a37032719b75
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.10
Status affected
Version 0
Version < 6.10
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc3
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.054
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/ab0159b1f7214ce9bad9862751e4553e635a21b1
https://git.kernel.org/stable/c/73a50c636425cb9f7ab647b5a97bd14dd5610076
https://git.kernel.org/stable/c/46884c0f92708f1d218fc94d88800227a19b52f8
https://git.kernel.org/stable/c/6436e1b5331b1aebf905c13e0880a37032719b75