In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: btusb: mediatek: Avoid btusb_mtk_claim_iso_intf() NULL deref
In btusb_mtk_setup(), we set `btmtk_data->isopkt_intf` to: usb_ifnum_to_if(data->udev, MTK_ISO_IFNUM)
That function can return NULL in some cases. Even when it returns NULL, though, we still go on to call btusb_mtk_claim_iso_intf().
As of commit e9087e828827 ("Bluetooth: btusb: mediatek: Add locks for usb_driver_claim_interface()"), calling btusb_mtk_claim_iso_intf() when `btmtk_data->isopkt_intf` is NULL will cause a crash because we'll end up passing a bad pointer to device_lock(). Prior to that commit we'd pass the NULL pointer directly to usb_driver_claim_interface() which would detect it and return an error, which was handled.
Resolve the crash in btusb_mtk_claim_iso_intf() by adding a NULL check at the start of the function. This makes the code handle a NULL `btmtk_data->isopkt_intf` the same way it did before the problematic commit (just with a slight change to the error message printed).
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 23, 2026 | Jul 23, 2026 |
| Oracle_linux | — | Upgrade kernel-uek | Feb 24, 2026 | Dec 16, 2025 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Dec 16, 2025 |
| Ubuntu | — | Upgrade linux-image-6.17.0-1010-azureUpgrade linux-image-generic-6.17Upgrade linux-image-oem-24.04aUpgrade linux-image-6.17.0-1009-oracleUpgrade linux-image-gcp-64kUpgrade linux-image-azure-6.17Upgrade linux-image-oem-24.04Upgrade linux-image-raspiUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-realtime-hwe-24.04Upgrade linux-image-oracle-64kUpgrade linux-image-virtual-hwe-24.04Upgrade linux-image-6.17.0-1009-aws-64kUpgrade linux-image-virtualUpgrade linux-image-realtime-6.17Upgrade linux-image-raspi-6.17Upgrade linux-image-6.17.0-1009-awsUpgrade linux-image-generic-64kUpgrade linux-image-genericUpgrade linux-image-aws-64kUpgrade linux-image-azureUpgrade linux-image-aws-6.17Upgrade linux-image-oem-24.04dUpgrade linux-image-gcpUpgrade linux-image-virtual-6.17Upgrade linux-image-6.17.0-19-generic-64kUpgrade linux-image-oracleUpgrade linux-image-oem-24.04bUpgrade linux-image-6.17.0-1009-gcp-64kUpgrade linux-image-6.17.0-1017-oemUpgrade linux-image-oracle-6.17Upgrade linux-image-6.17.0-1010-raspiUpgrade linux-image-oem-6.17Upgrade linux-image-awsUpgrade linux-image-6.17.0-1009-oracle-64kUpgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-6.17.0-1009-gcpUpgrade linux-image-6.17.0-19-genericUpgrade linux-image-aws-64k-6.17Upgrade linux-image-oracle-64k-6.17Upgrade linux-image-gcp-64k-6.17Upgrade linux-image-6.17.0-1008-realtimeUpgrade linux-image-generic-64k-6.17Upgrade linux-image-oem-24.04cUpgrade linux-image-realtimeUpgrade linux-image-gcp-6.17 | Mar 17, 2026 | Dec 16, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub