-
CVE-2026-98296
- EPSS 0.21%
- Veröffentlicht 06.10.2026 08:45:55
- Zuletzt bearbeitet 06.10.2026 09:18:20
- Erkennungen
Bluetooth: btintel_pcie: validate TX skb length in send_sync
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel_pcie: validate TX skb length in send_sync btintel_pcie_prepare_tx() copies skb->len bytes into a fixed BTINTEL_PCIE_BUFFER_SIZE (4096) DMA slot via an unchecked memcpy. Oversized packets are currently rejected only in btintel_pcie_send_frame(); any future caller of btintel_pcie_send_sync() would silently overflow the DMA buffer. Add the bounds check in btintel_pcie_send_sync() itself, right before skb_push() and the DMA copy.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
6e65a09f927566f257322358d429b267548473eb
Version <
84f353256e170dc4865d45007d1bc446ed566da7
Status
affected
Version
6e65a09f927566f257322358d429b267548473eb
Version <
c298a61e18029401486c40298a50fbeea7e7b663
Status
affected
Version
6e65a09f927566f257322358d429b267548473eb
Version <
4b837ebd0ea21ae5cc26f02dc042edc6fe7b46b9
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.10
Status
affected
Version
0
Version <
6.10
Status
unaffected
Version <=
6.18.*
Version
6.18.54
Status
unaffected
Version <=
7.2.*
Version
7.2.8
Status
unaffected
Version <=
*
Version
7.3-rc4
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.21% | 0.098 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/84f353256e170dc4865d45007d1bc446ed566da7
https://git.kernel.org/stable/c/c298a61e18029401486c40298a50fbeea7e7b663
https://git.kernel.org/stable/c/4b837ebd0ea21ae5cc26f02dc042edc6fe7b46b9