« Volver al listado

CVE-2025-68298

Estado: AplazadaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: btusb: mediatek: Avoid btusb_mtk_claim_iso_intf() NULL deref

That function can return NULL in some cases. Even when it returns NULL, though, we still go on to call btusb_mtk_claim_iso_intf().

As of commit e9087e828827 ("Bluetooth: btusb: mediatek: Add locks for usb_driver_claim_interface()"), calling btusb_mtk_claim_iso_intf() when `btmtk_data->isopkt_intf` is NULL will cause a crash because we'll end up passing a bad pointer to device_lock(). Prior to that commit we'd pass the NULL pointer directly to usb_driver_claim_interface() which would detect it and return an error, which was handled.

Leer descripción completaMostrar menos

Resolve the crash in btusb_mtk_claim_iso_intf() by adding a NULL check at the start of the function. This makes the code handle a NULL `btmtk_data->isopkt_intf` the same way it did before the problematic commit (just with a slight change to the error message printed).

Detalles técnicos trazas, registros y código del informe original
In btusb_mtk_setup(), we set `btmtk_data->isopkt_intf` to:
  usb_ifnum_to_if(data->udev, MTK_ISO_IFNUM)

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-68298",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "930e1790b99e5839e1af69d2f7fd808f1fba2df9",
              "lessThan": "2fa09fe98ca3b114d66285f65f7e108fea131815",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e9087e828827e5a5c85e124ce77503f2b81c3491",
              "lessThan": "c3b990e0b23068da65f0004cd38ee31f43f36460",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e9087e828827e5a5c85e124ce77503f2b81c3491",
              "lessThan": "c884a0b27b4586e607431d86a1aa0bb4fb39169c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4194766ec8756f4f654d595ae49962acbac49490",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.12.13",
              "lessThan": "6.12.61",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.13.2",
              "lessThan": "6.14",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "drivers/bluetooth/btusb.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.14"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.14",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.61",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.17.11",
              "versionType": "semver",
              "lessThanOrEqual": "6.17.*"
            },
            {
              "status": "unaffected",
              "version": "6.18",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/bluetooth/btusb.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-12-16T16:16:08.760",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/2fa09fe98ca3b114d66285f65f7e108fea131815",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c3b990e0b23068da65f0004cd38ee31f43f36460",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c884a0b27b4586e607431d86a1aa0bb4fb39169c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Deferred",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btusb: mediatek: Avoid btusb_mtk_claim_iso_intf() NULL deref\n\nIn btusb_mtk_setup(), we set `btmtk_data->isopkt_intf` to:\n  usb_ifnum_to_if(data->udev, MTK_ISO_IFNUM)\n\nThat function can return NULL in some cases. Even when it returns\nNULL, though, we still go on to call btusb_mtk_claim_iso_intf().\n\nAs of commit e9087e828827 (\"Bluetooth: btusb: mediatek: Add locks for\nusb_driver_claim_interface()\"), calling btusb_mtk_claim_iso_intf()\nwhen `btmtk_data->isopkt_intf` is NULL will cause a crash because\nwe'll end up passing a bad pointer to device_lock(). Prior to that\ncommit we'd pass the NULL pointer directly to\nusb_driver_claim_interface() which would detect it and return an\nerror, which was handled.\n\nResolve the crash in btusb_mtk_claim_iso_intf() by adding a NULL check\nat the start of the function. This makes the code handle a NULL\n`btmtk_data->isopkt_intf` the same way it did before the problematic\ncommit (just with a slight change to the error message printed)."
    }
  ],
  "lastModified": "2026-06-17T09:58:53.627",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}