PT-2025-51710 · Mediatek+5 · Btusb Mediatek+5

CVE-2025-68306

·

Published

2025-11-12

·

Updated

2026-04-06

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a flaw within the Bluetooth subsystem, specifically in the btusb mediatek component. A null pointer dereference can occur when releasing the MediaTek ISO interface, potentially leading to a kernel crash during reset tests or abnormal card drop scenarios. The issue arises from a missing null check before attempting to release resources. The crash has been observed on Google Quigon devices. The function btusb mtk release iso intf() is involved in the crash.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-11987
CVE-2025-68306
OPENSUSE-SU-2026:20145-1
SUSE-SU-2026:0278-1
SUSE-SU-2026:0281-1
SUSE-SU-2026:0315-1
SUSE-SU-2026:20207-1
SUSE-SU-2026:20220-1
SUSE-SU-2026:20228-1
SUSE-SU-2026:20564-1
USN-8094-1
USN-8094-2
USN-8094-3
USN-8094-4
USN-8094-5
USN-8152-1

Affected Products

Debian
Google Quigon
Linuxmint
Linux Kernel
Ubuntu
Btusb Mediatek