KernelScan.io

HIGH Introduced in 6.10

btintel_pcie RxSubmit OOB

CVE-2026-98291

CVSS 8.8 / 10.0 KernelScan AI

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

01

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel_pcie: fix off-by-one bounds check in RX submit btintel_pcie_submit_rx() used frbd_index > rxq->count to guard the FRBD array access, allowing frbd_index == rxq->count to pass through and index one element past the end of the array. Change the check to >= rxq->count so every out-of-range index is rejected. This issue was reported by Claude Mythos.

02

Engine v0.7.0

Risk summary

An off-by-one bounds check in the Intel Bluetooth PCIe RX submission path allows an out-of-bounds write one element past the end of a buffer descriptor array. An attacker within Bluetooth range of a system with an Intel Bluetooth PCIe controller can trigger this by generating RX traffic, potentially corrupting kernel heap memory and causing a crash or worse. No local account or special privileges are required.

Affecteddrivers/bluetooth/btintel_pcie.c (Intel Bluetooth PCIe driver)

Vulnerability analysis

The Intel Bluetooth PCIe driver's receive buffer submission routine checks whether a ring-buffer index is within bounds before using it to access an array of free receive buffer descriptors. The check used a strictly-greater-than comparison, so an index equal to the array size passed through and caused an out-of-bounds access one element past the end of the array. The fix changes the comparison to greater-than-or-equal, rejecting every out-of-range index. The vulnerable code path is reached when the driver processes incoming Bluetooth data on systems equipped with an Intel Bluetooth PCIe controller; an attacker within Bluetooth radio proximity can generate the RX traffic needed to trigger the corruption without any local account or privileges.

03

BranchIntroducedFixed inPatch commit
6.126.106.12.112b5214d72bfdf
6.186.106.18.5418464860ce27
7.26.107.2.8de4c3c72bcc6
mainline6.107.3-rc42ea5a87a5a7a