« Volver al listado

CVE-2026-97976

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: btintel_pcie: validate packet_len before skb_put_data

btintel_pcie_submit_rx_work() reads packet_len from rfh_hdr without checking if it exceeds the RX buffer size. An oversized packet_len can lead to an out-of-bounds read in skb_put_data().

Validate packet_len to ensure it is non-zero and does not exceed BTINTEL_PCIE_BUFFER_SIZE - sizeof(*rfh_hdr), logging an error when invalid.

This issue was reported by Claude Mythos. It can be simulated either by using customized firmware configured to return an invalid packet_len or by modifying rfh_hdr->packet_len in the driver before calling btintel_pcie_submit_rx_work().

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-97976",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "c2b636b3f788d10486a6691ad6dd3ec4c93bd78e",
              "lessThan": "ab0159b1f7214ce9bad9862751e4553e635a21b1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c2b636b3f788d10486a6691ad6dd3ec4c93bd78e",
              "lessThan": "73a50c636425cb9f7ab647b5a97bd14dd5610076",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c2b636b3f788d10486a6691ad6dd3ec4c93bd78e",
              "lessThan": "46884c0f92708f1d218fc94d88800227a19b52f8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c2b636b3f788d10486a6691ad6dd3ec4c93bd78e",
              "lessThan": "6436e1b5331b1aebf905c13e0880a37032719b75",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/bluetooth/btintel_pcie.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.10"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.10",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc3",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/bluetooth/btintel_pcie.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:25.570",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/46884c0f92708f1d218fc94d88800227a19b52f8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6436e1b5331b1aebf905c13e0880a37032719b75",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/73a50c636425cb9f7ab647b5a97bd14dd5610076",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ab0159b1f7214ce9bad9862751e4553e635a21b1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btintel_pcie: validate packet_len before skb_put_data\n\nbtintel_pcie_submit_rx_work() reads packet_len from rfh_hdr without\nchecking if it exceeds the RX buffer size. An oversized packet_len\ncan lead to an out-of-bounds read in skb_put_data().\n\nValidate packet_len to ensure it is non-zero and does not exceed\nBTINTEL_PCIE_BUFFER_SIZE - sizeof(*rfh_hdr), logging an error when\ninvalid.\n\nThis issue was reported by Claude Mythos. It can be simulated either by\nusing customized firmware configured to return an invalid packet_len or\nby modifying rfh_hdr->packet_len in the driver before calling\nbtintel_pcie_submit_rx_work()."
    }
  ],
  "lastModified": "2026-09-25T11:17:25.570",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}