Answer in brief
CVE-2026-98291 records a Unknown severity vulnerability in Bluetooth: btintel_pcie: fix off-by-one bounds check in RX submit. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=c2b636b3f788d10486a6691ad6dd3ec4c93bd78e <b5214d72bfdf8ef7744d0c8147e6ebb09b36b259 || >=c2b636b3f788d10486a6691ad6dd3ec4c93bd78e <18464860ce27af0dccd2fc72830610b85b518cff || >=c2b636b3f788d10486a6691ad6dd3ec4c93bd78e <de4c3c72bcc6e8474f70c22427f94ca44bccd890 || >=c2b636b3f788d10486a6691ad6dd3ec4c93bd78e <2ea5a87a5a7ae58cb2662b8a7d06f209383e1765 | b5214d72bfdf8ef7744d0c8147e6ebb09b36b259, 18464860ce27af0dccd2fc72830610b85b518cff, de4c3c72bcc6e8474f70c22427f94ca44bccd890, 2ea5a87a5a7ae58cb2662b8a7d06f209383e1765 |
| Linux/Linuxgeneric | 6.10 | Not reported |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel_pcie: fix off-by-one bounds check in RX submit btintel_pcie_submit_rx() used frbd_index > rxq->count to guard the FRBD array access, allowing frbd_index == rxq->count to pass through and index one element past the end of the array. Change the check to >= rxq->count so every out-of-range index is rejected. This issue was reported by Claude Mythos.
Quoted source text, attributed separately from HOL analysis.