-

CVE-2026-98296

Bluetooth: btintel_pcie: validate TX skb length in send_sync

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: btintel_pcie: validate TX skb length in send_sync

btintel_pcie_prepare_tx() copies skb->len bytes into a fixed
BTINTEL_PCIE_BUFFER_SIZE (4096) DMA slot via an unchecked memcpy.
Oversized packets are currently rejected only in
btintel_pcie_send_frame(); any future caller of
btintel_pcie_send_sync() would silently overflow the DMA buffer.

Add the bounds check in btintel_pcie_send_sync() itself, right
before skb_push() and the DMA copy.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 6e65a09f927566f257322358d429b267548473eb
Version < 84f353256e170dc4865d45007d1bc446ed566da7
Status affected
Version 6e65a09f927566f257322358d429b267548473eb
Version < c298a61e18029401486c40298a50fbeea7e7b663
Status affected
Version 6e65a09f927566f257322358d429b267548473eb
Version < 4b837ebd0ea21ae5cc26f02dc042edc6fe7b46b9
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.10
Status affected
Version 0
Version < 6.10
Status unaffected
Version <= 6.18.*
Version 6.18.54
Status unaffected
Version <= 7.2.*
Version 7.2.8
Status unaffected
Version <= *
Version 7.3-rc4
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.098
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/84f353256e170dc4865d45007d1bc446ed566da7
https://git.kernel.org/stable/c/c298a61e18029401486c40298a50fbeea7e7b663
https://git.kernel.org/stable/c/4b837ebd0ea21ae5cc26f02dc042edc6fe7b46b9