Answer in brief
CVE-2026-98296 records a Unknown severity vulnerability in Bluetooth: btintel_pcie: validate TX skb length in send_sync. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=6e65a09f927566f257322358d429b267548473eb <84f353256e170dc4865d45007d1bc446ed566da7 || >=6e65a09f927566f257322358d429b267548473eb <c298a61e18029401486c40298a50fbeea7e7b663 || >=6e65a09f927566f257322358d429b267548473eb <4b837ebd0ea21ae5cc26f02dc042edc6fe7b46b9 | 84f353256e170dc4865d45007d1bc446ed566da7, c298a61e18029401486c40298a50fbeea7e7b663, 4b837ebd0ea21ae5cc26f02dc042edc6fe7b46b9 |
| Linux/Linuxgeneric | 6.10 | Not reported |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel_pcie: validate TX skb length in send_sync btintel_pcie_prepare_tx() copies skb->len bytes into a fixed BTINTEL_PCIE_BUFFER_SIZE (4096) DMA slot via an unchecked memcpy. Oversized packets are currently rejected only in btintel_pcie_send_frame(); any future caller of btintel_pcie_send_sync() would silently overflow the DMA buffer. Add the bounds check in btintel_pcie_send_sync() itself, right before skb_push() and the DMA copy.
Quoted source text, attributed separately from HOL analysis.