Infinite loop in Linux kernel - CVE-2026-64409
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper loop termination in btmtksdio_txrx_work() when processing Bluetooth SDIO transmit and receive work. A local user can trigger repeated pending interrupt handling to cause a denial of service.
The issue can cause the workqueue to loop indefinitely and prevent release of the SDIO host.
Affected software
How to mitigate CVE-2026-64409
External References
- https://git.kernel.org/stable/c/0039bdde36b23ccf1196635f1d52c5490481544d
- https://git.kernel.org/stable/c/0f0a83e26a9c7fd4b243c315ce07161d2496d83d
- https://git.kernel.org/stable/c/466540e045d01fcacf383a5beb8a2dad2fc53a26
- https://git.kernel.org/stable/c/7b429d611060e87752e848851815537963726493
- https://git.kernel.org/stable/c/a257407e2bbbb099ed427719a50563f67fa366d8
- https://git.kernel.org/stable/c/f6682c23b6fac4780d297ae4662053d17e58fd52