---
id: CVE-2026-97907
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  Bluetooth: btrtl: Don't leak return code when parsing firmware format v2

  When key_id from chip is zero, rtlbt_parse_firmware_v2() intentionally
  ignores all security he…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  Bluetooth: btrtl: Don't leak return code when parsing firmware format v2

  When key_id from chip is zero, rtlbt_parse_firmware_v2() intentionally
  ignores all security he…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 9a24ce5e29b15c4c6b0c89c04f9df6ce14addefa <
    90f3a142b5f8596a565b8e080d18a8050be6edef
  - >-
    Linux >= 9a24ce5e29b15c4c6b0c89c04f9df6ce14addefa <
    422f6547259654bae690713614c794dd1e2c0a0b
  - >-
    Linux >= 9a24ce5e29b15c4c6b0c89c04f9df6ce14addefa <
    c4249cf6e80b1bd62a6a409aaabe760fe025dac3
  - >-
    Linux >= 9a24ce5e29b15c4c6b0c89c04f9df6ce14addefa <
    83e3e515fd261600ed8491fb0a8bcdfb115c904e
  - Linux 6.4
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T11:17:17.627'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-97907'
references:
  - url: 'https://git.kernel.org/stable/c/422f6547259654bae690713614c794dd1e2c0a0b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/83e3e515fd261600ed8491fb0a8bcdfb115c904e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/90f3a142b5f8596a565b8e080d18a8050be6edef'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/c4249cf6e80b1bd62a6a409aaabe760fe025dac3'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-25T11:06:38.893Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: btrtl: Don't leak return code when parsing firmware format v2

When key_id from chip is zero, rtlbt_parse_firmware_v2() intentionally
ignores all security headers. However, the implementation simply breaks
from a switch statement and leaks uninitialized return code `rc' (if the
first section is a security one) or the previous section's `rc'.

Fix it by really skipping a loop with `continue'. For consistency and
readability, also do the same for the default case.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
