---
cve: "CVE-2026-64409"
severity: "LOW"
cvss: 3.1
epss: "17%"
vendor: "Linux"
kev: false
exploited: false
published: "2026-07-25 08:50:50"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-05T15:49:10+02:00"
---

# CVE-2026-64409

> 3.1 LOW

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work()

Every once in a while we see a hung btmtksdio_flush() task:

 INFO: task kworker/u17:0:189 blocked for more than 122 seconds.
 __cancel_work_timer+0x3f4/0x460
 cancel_work_sync+0x1c/0x2c
 btmtksdio_flush+0x2c/0x40
 hci_dev_open_sync+0x10c4/0x2190
 [..]

It all boils down to incorrect time_is_before_jiffies() usage in
btmtksdio_txrx_work().  The btmtksdio_txrx_work() loop is expected
to be terminated if running for longer than 5*HZ.  However the
timeout check is twisted:  time_is_before_jiffies(old_jiffies + 5*HZ)
evaluates to true when old_jiffies + 5*HZ is in the past i.e. when a
timeout has occurred.  Using OR with time_is_before_jiffies(txrx_timeout)
means that:
- before the 5-second timeout: the condition is `int_status || false`,
  so it loops as long as there are pending interrupts.
- after the 5-second timeout: the condition becomes `int_status || true`,
  which is always true.

When the loop becomes infinite btmtksdio_txrx_work() loop never
terminates and never releases the SDIO host.

Fix loop termination condition to actually enforce a 5*HZ timeout.

## Patch verfügbar (OSV)

- Kernel ≥ 6.1.178
- Kernel ≥ 6.6.145
- Kernel ≥ 6.12.96
- Kernel ≥ 6.18.39
- Kernel ≥ 7.1.4

## Referenzen

- <https://git.kernel.org/stable/c/f6682c23b6fac4780d297ae4662053d17e58fd52>
- <https://git.kernel.org/stable/c/466540e045d01fcacf383a5beb8a2dad2fc53a26>
- <https://git.kernel.org/stable/c/7b429d611060e87752e848851815537963726493>
- <https://git.kernel.org/stable/c/0039bdde36b23ccf1196635f1d52c5490481544d>
- <https://git.kernel.org/stable/c/0f0a83e26a9c7fd4b243c315ce07161d2496d83d>
- <https://git.kernel.org/stable/c/a257407e2bbbb099ed427719a50563f67fa366d8>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-64409) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
