{"id":"CVE-2026-98291","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btintel_pcie: fix off-by-one bounds check in RX submit\n\nbtintel_pcie_submit_rx() used frbd_index > rxq->count to guard the\nFRBD array access, allowing frbd_i…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btintel_pcie: fix off-by-one bounds check in RX submit\n\nbtintel_pcie_submit_rx() used frbd_index > rxq->count to guard the\nFRBD array access, allowing frbd_i…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= c2b636b3f788d10486a6691ad6dd3ec4c93bd78e < b5214d72bfdf8ef7744d0c8147e6ebb09b36b259","Linux >= c2b636b3f788d10486a6691ad6dd3ec4c93bd78e < 18464860ce27af0dccd2fc72830610b85b518cff","Linux >= c2b636b3f788d10486a6691ad6dd3ec4c93bd78e < de4c3c72bcc6e8474f70c22427f94ca44bccd890","Linux >= c2b636b3f788d10486a6691ad6dd3ec4c93bd78e < 2ea5a87a5a7ae58cb2662b8a7d06f209383e1765","Linux 6.10"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:18:19.467","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98291","references":[{"url":"https://git.kernel.org/stable/c/18464860ce27af0dccd2fc72830610b85b518cff","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2ea5a87a5a7ae58cb2662b8a7d06f209383e1765","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b5214d72bfdf8ef7744d0c8147e6ebb09b36b259","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/de4c3c72bcc6e8474f70c22427f94ca44bccd890","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T08:50:17.416Z","slug":"CVE-2026-98291","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btintel_pcie: fix off-by-one bounds check in RX submit\n\nbtintel_pcie_submit_rx() used frbd_index > rxq->count to guard the\nFRBD array access, allowing frbd_index == rxq->count to pass through\nand index one element past the end of the array. Change the check to\n>= rxq->count so every out-of-range index is rejected.\n\nThis issue was reported by Claude Mythos.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}