Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-64409

Published Jul 25, 2026 EPSS 0.17% (7th pctl)

Overview

CVE-2026-64409 is a known-severity vulnerability. It was published on July 25, 2026.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work()

Every once in a while we see a hung btmtksdio_flush() task:

INFO: task kworker/u17:0:189 blocked for more than 122 seconds.

__cancel_work_timer+0x3f4/0x460

cancel_work_sync+0x1c/0x2c

btmtksdio_flush+0x2c/0x40

hci_dev_open_sync+0x10c4/0x2190

[..]

It all boils down to incorrect time_is_before_jiffies() usage in

btmtksdio_txrx_work(). The btmtksdio_txrx_work() loop is expected

to be terminated if running for longer than 5*HZ. However the

timeout check is twisted: time_is_before_jiffies(old_jiffies + 5*HZ)

evaluates to true when old_jiffies + 5*HZ is in the past i.e. when a

timeout has occurred. Using OR with time_is_before_jiffies(txrx_timeout)

means that:

- before the 5-second timeout: the condition is `int_status || false`,

so it loops as long as there are pending interrupts.

- after the 5-second timeout: the condition becomes `int_status |

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-64409?

CVE-2026-64409 is a known-severity vulnerability. It was published on July 25, 2026.

How severe is CVE-2026-64409?

CVSS score information is not yet available for this vulnerability. Check back as the CVE record is updated by NVD analysts.

How do I fix or remediate CVE-2026-64409?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-64409?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-64409 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.