CVE-2026-98291: Bluetooth: btintel_pcie: fix off-by-one bounds check in RX submit
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: btintelpcie: fix off-by-one bounds check in RX submit
btintelpciesubmitrx() used frbdindex > rxq->count to guard the FRBD array access, allowing frbdindex == rxq->count to pass through and index one element past the end of the array. Change the check to = rxq->count so every out-of-range index is rejected.
This issue was reported by Claude Mythos.
Affected Software
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
Systems running the Linux kernel with the btintel_pcie Bluetooth driver are relevant. The issue is in the driver's RX submission path and concerns an out-of-bounds FRBD array access when the index equals the receive-queue count.
What condition triggers the out-of-bounds access?
The access can occur when frbd_index is exactly equal to rxq->count. The previous check rejected only values greater than the count, allowing this one-past-the-end index to proceed.
How can I determine whether the fix is present?
Check whether btintel_pcie_submit_rx() rejects frbd_index values greater than or equal to rxq->count. A fixed version uses a >= rxq->count bounds check rather than > rxq->count.
What can be done if updating is not immediately possible?
The provided information does not describe a configuration workaround. Prioritize applying a kernel update that includes the corrected bounds check.