CVE-2026-98296EPSS p9.8%
CVE-2026-98296CVE-2026-98296
Description
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: btintel_pcie: validate TX skb length in send_sync
btintel_pcie_prepare_tx() copies skb->len bytes into a fixed
BTINTEL_PCIE_BUFFER_SIZE (4096) DMA slot via an unchecked memcpy.
Oversized packets are currently rejected only in
btintel_pcie_send_frame(); any future caller of
btintel_pcie_send_sync() would silently overflow the DMA buffer.
Add the bounds check in btintel_pcie_send_sync() itself, right
before skb_push() and the DMA copy.
Scoring
| EPSS | 0.21% probability of exploitation · percentile 9.8% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-06 |