CVE-2026-64409 Details
Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() Every once in a while we see a hung btmtksdio_flush() task: INFO: task kworker/u17:0:189 blocked for more than 122 seconds. __cancel_work_timer+0x3f4/0x460 cancel_work_sync+0x1c/0x2c btmtksdio_flush+0x2c/0x40 hci_dev_open_sync+0x10c4/0x2190 [..] It all boils down to incorrect time_is_before_jiffies() usage in btmtksdio_txrx_work(). The btmtksdio_txrx_work() loop is expected to be terminated if running for longer than 5*HZ. However the timeout check is twisted: time_is_before_jiffies(old_jiffies + 5*HZ) evaluates to true when old_jiffies + 5*HZ is in the past i.e. when a timeout has occurred. Using OR with time_is_before_jiffies(txrx_timeout) means that: - before the 5-second timeout: the condition is `int_status || false`, so it loops as long as there are pending interrupts. - after the 5-second timeout: the condition becomes `int_status || true`, which is always true. When the loop becomes infinite btmtksdio_txrx_work() loop never terminates and never releases the SDIO host. Fix loop termination condition to actually enforce a 5*HZ timeout.
A vulnerability in the Linux kernel's Bluetooth btmtksdio driver can lead to an infinite loop in the btmtksdio_txrx_work() function. This issue causes the btmtksdio_flush() task to hang, blocking for an extended period. The problem arises from improper use of the time_is_before_jiffies() function, which creates a faulty timeout condition. As a result, the loop can run indefinitely, preventing the SDIO host from being released. This vulnerability affects the Linux kernel stable tree.
The vulnerability has been fixed in the Linux kernel. Users can apply the latest patches available in the Linux kernel stable tree to address this issue.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/0039bdde36b23ccf1196635f1d52c5490481544d | kernel.org | Patch |
| https://git.kernel.org/stable/c/0f0a83e26a9c7fd4b243c315ce07161d2496d83d | kernel.org | Patch |
| https://git.kernel.org/stable/c/466540e045d01fcacf383a5beb8a2dad2fc53a26 | kernel.org | Patch |
| https://git.kernel.org/stable/c/7b429d611060e87752e848851815537963726493 | kernel.org | Patch |
| https://git.kernel.org/stable/c/a257407e2bbbb099ed427719a50563f67fa366d8 | kernel.org | Patch |
| https://git.kernel.org/stable/c/f6682c23b6fac4780d297ae4662053d17e58fd52 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-835 | Loop with Unreachable Exit Condition ('Infinite Loop') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 5.17, < 6.1.178 >= 6.2, < 6.6.145 >= 6.7, < 6.12.96 >= 6.13, < 6.18.39 >= 6.19, < 7.1.4 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 4, 2026 | Initial Analysis | [email protected] |
| Aug 17, 2026 | CVE Modified | kernel.org |
| Jul 25, 2026 | New CVE Received | kernel.org |