Out-of-bounds read in Linux kernel - CVE-2026-97976
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local privileged user to perform an out-of-bounds read.
The vulnerability exists due to improper bounds checking in btintel_pcie_submit_rx_work() when processing RX packets with a packet_len value from rfh_hdr. A local privileged user can provide an oversized packet_len value to perform an out-of-bounds read.