CVE-2026-98291

Source
https://cve.org/CVERecord?id=CVE-2026-98291
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98291.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98291
Downstream
Published
2026-10-06T08:45:51Z
Modified
2026-10-08T02:52:56Z
Summary
Bluetooth: btintel_pcie: fix off-by-one bounds check in RX submit
Details

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: btintel_pcie: fix off-by-one bounds check in RX submit

btintel_pcie_submit_rx() used frbd_index > rxq->count to guard the FRBD array access, allowing frbd_index == rxq->count to pass through and index one element past the end of the array. Change the check to

= rxq->count so every out-of-range index is rejected.

This issue was reported by Claude Mythos.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98291.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c2b636b3f788d10486a6691ad6dd3ec4c93bd78e
Fixed
b5214d72bfdf8ef7744d0c8147e6ebb09b36b259
Fixed
18464860ce27af0dccd2fc72830610b85b518cff
Fixed
de4c3c72bcc6e8474f70c22427f94ca44bccd890
Fixed
2ea5a87a5a7ae58cb2662b8a7d06f209383e1765

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98291.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.10.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98291.json"