Off-by-one in Linux kernel - CVE-2026-98291
Published: October 7, 2026
Vulnerability details
The vulnerability allows a local user to cause an out-of-bounds access to the FRBD array.
The vulnerability exists due to an off-by-one bounds check in btintel_pcie_submit_rx() when submitting receive buffers. A local user can trigger RX submission with an FRBD index equal to the RX queue count to cause an out-of-bounds access to the FRBD array.