CVE-2025-68306
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-68306 is a null pointer dereference vulnerability in the Linux kernel's Bluetooth btusb driver for MediaTek devices, specifically in the btusb_mtk_release_iso_intf function. The flaw occurs when releasing the MediaTek ISO interface during reset operations or abnormal device disconnection (card drop) scenarios, where a null pointer dereference triggers a kernel panic. It was disclosed on December 16, 2025, and affects Linux kernel versions prior to the fix commits. It carries a CVSS v3.1 base score of 5.5 (Medium), with a local attack vector and high availability impact (Red Hat Advisory, Red Hat Bugzilla).

Technical details

The root cause is a missing null pointer check (CWE-476) in the btusb_mtk_release_iso_intf function within the Linux kernel's btusb driver for MediaTek Bluetooth USB devices. During a Bluetooth reset (btusb_mtk_reset) or abnormal card removal, the function attempts to call usb_driver_release_interface on a potentially null interface pointer, leading to a kernel panic via klist_remove. The crash trace shows the fault occurring at klist_remove+0x90/0x158, called through device_release_driver_internalusb_driver_release_interfacebtusb_mtk_release_iso_intf. The fix adds a null check before attempting to release the interface resource (Red Hat Bugzilla).

Impact

Successful exploitation causes a kernel panic and complete system crash (denial of service), as evidenced by the Kernel panic - not syncing: Oops: Fatal exception message in the crash trace. There is no confidentiality or integrity impact — the vulnerability is limited to availability. Systems using MediaTek Bluetooth USB adapters (e.g., devices running on Google Quigon boards or similar ARM-based platforms with MediaTek BT chipsets) are at risk of unexpected reboots or service interruption when Bluetooth reset or abnormal disconnection events occur (Red Hat Advisory, Red Hat Bugzilla).

Mitigation and workarounds

The fix is included in patched Linux kernel versions via upstream stable commits (e.g., 421e88a0d857, 4015b9797671, faae9f2ea880). Downstream distributions have issued advisories: Ubuntu has released USN-8094-1 through USN-8094-5 and USN-8152-1, and Oracle has released ELSA-2026-50112. Users should update to the latest patched kernel version for their distribution. As a temporary workaround, disabling Bluetooth services (systemctl disable bluetooth) on affected systems with MediaTek USB Bluetooth adapters can prevent the crash from occurring (Red Hat Advisory, Ubuntu USN-8094-1).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management