CVE-2026-98296: Bluetooth: btintel_pcie: validate TX skb length in send_sync
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: btintelpcie: validate TX skb length in sendsync
btintelpciepreparetx() copies skb->len bytes into a fixed BTINTELPCIEBUFFERSIZE (4096) DMA slot via an unchecked memcpy. Oversized packets are currently rejected only in btintelpciesendframe(); any future caller of btintelpciesendsync() would silently overflow the DMA buffer.
Add the bounds check in btintelpciesendsync() itself, right before skbpush() and the DMA copy.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Add a bounds check in btintel_pcie_send_sync() to validate the TX skb length against BTINTEL_PCIE_BUFFER_SIZE (4096) and reject oversized packets before skb_push() and the DMA copy.