HIGH Introduced in 6.10
btintel_pcie RxSubmit OOB
CVE-2026-98291
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
01Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel_pcie: fix off-by-one bounds check in RX submit btintel_pcie_submit_rx() used frbd_index > rxq->count to guard the FRBD array access, allowing frbd_index == rxq->count to pass through and index one element past the end of the array. Change the check to >= rxq->count so every out-of-range index is rejected. This issue was reported by Claude Mythos.
02KernelScan AI Analysis
Risk summary
An off-by-one bounds check in the Intel Bluetooth PCIe RX submission path allows an out-of-bounds write one element past the end of a buffer descriptor array. An attacker within Bluetooth range of a system with an Intel Bluetooth PCIe controller can trigger this by generating RX traffic, potentially corrupting kernel heap memory and causing a crash or worse. No local account or special privileges are required.
Vulnerability analysis
The Intel Bluetooth PCIe driver's receive buffer submission routine checks whether a ring-buffer index is within bounds before using it to access an array of free receive buffer descriptors. The check used a strictly-greater-than comparison, so an index equal to the array size passed through and caused an out-of-bounds access one element past the end of the array. The fix changes the comparison to greater-than-or-equal, rejecting every out-of-range index. The vulnerable code path is reached when the driver processes incoming Bluetooth data on systems equipped with an Intel Bluetooth PCIe controller; an attacker within Bluetooth radio proximity can generate the RX traffic needed to trigger the corruption without any local account or privileges.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.12 | 6.10 | 6.12.112 | b5214d72bfdf |
| 6.18 | 6.10 | 6.18.54 | 18464860ce27 |
| 7.2 | 6.10 | 7.2.8 | de4c3c72bcc6 |
| mainline | 6.10 | 7.3-rc4 | 2ea5a87a5a7a |