{"id":"CVE-2026-97976","summary":"Bluetooth: btintel_pcie: validate packet_len before skb_put_data","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btintel_pcie: validate packet_len before skb_put_data\n\nbtintel_pcie_submit_rx_work() reads packet_len from rfh_hdr without\nchecking if it exceeds the RX buffer size. An oversized packet_len\ncan lead to an out-of-bounds read in skb_put_data().\n\nValidate packet_len to ensure it is non-zero and does not exceed\nBTINTEL_PCIE_BUFFER_SIZE - sizeof(*rfh_hdr), logging an error when\ninvalid.\n\nThis issue was reported by Claude Mythos. It can be simulated either by\nusing customized firmware configured to return an invalid packet_len or\nby modifying rfh_hdr-\u003epacket_len in the driver before calling\nbtintel_pcie_submit_rx_work().","modified":"2026-09-26T03:48:27.919244480Z","published":"2026-09-25T10:23:14.596Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97976.json","cna_assigner":"Linux"},"references":[{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"},{"type":"WEB","url":"https://git.kernel.org/stable/c/46884c0f92708f1d218fc94d88800227a19b52f8"},{"type":"WEB","url":"https://git.kernel.org/stable/c/6436e1b5331b1aebf905c13e0880a37032719b75"},{"type":"WEB","url":"https://git.kernel.org/stable/c/73a50c636425cb9f7ab647b5a97bd14dd5610076"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ab0159b1f7214ce9bad9862751e4553e635a21b1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97976.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97976"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"c2b636b3f788d10486a6691ad6dd3ec4c93bd78e"},{"fixed":"ab0159b1f7214ce9bad9862751e4553e635a21b1"},{"fixed":"73a50c636425cb9f7ab647b5a97bd14dd5610076"},{"fixed":"46884c0f92708f1d218fc94d88800227a19b52f8"},{"fixed":"6436e1b5331b1aebf905c13e0880a37032719b75"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97976.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.10.0"},{"fixed":"6.12.111"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.53"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.7"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97976.json"}}],"schema_version":"1.9.0"}