The Register Home Page

back to article Out-of-band getting out of hand as Microsoft pushes hotpatch for Bluetooth

Microsoft has pushed out yet another out-of-band hotpatch, this time to fix Bluetooth issues in Windows 11 25H2 and 24H2. The hotpatch applies only to hotpatch-enabled devices and arrives the same month Microsoft said that hotpatching would become the default for Windows Autopatch. This is the second out-of-band hotpatch in a …

  1. xanadu42
    Facepalm

    "Out-of-band updates have arrived with depressing regularity in recent months"

    Add "hotpatching" and "copilot" into the mix of Windows Updates and it seems inevitable to me that the 2024 "Crowdstrike Outage" will, in the not-too-distant-future, be reported-in-passing as a "minor outage" of Windows Machines...

    1. Strahd Ivarius Silver badge
      Devil

      As long as any world-class outage affects first the USA, and the issue is solved before it reaches civilized countries, I don't care much...

      1. Eric 9001

        With microsoft that won't happen, as there have been many cases where a know defective update has been pushed out worldwide regardless - since why would they care - as if you are still being used by windows in 2026, you must obey and be grateful that anything works at all.

        I suspect the original update that broke bluetooth is yet another case of that happening.

      2. David Hicklin Silver badge

        Sadly the far East and Europe/Africa are ahead of USA time/date wise, so the poor users there are always the Alpha testers.

        It is almost sounding like Micro$lop are slowly reverting to just shoving a fix out as and when needed just like the good old days....

        1. hoola Silver badge

          This endless deployment of patches is not just Microsoft. It is a symptom of the wider malaise we have now in software where quality and testing is optional.

          I see this attributed to two things:

          Pushing development out to countries with the lowest cost.

          Agile methodology.

          I am sick of the crap that comes out of Agile development but it does not appear to matter how poor the quality is the mantra "fix it in the next sprint " is used. The outcome is another pile of shite that is barely functional.

          1. nonpc

            It's also sticking plaster on top of sticking plaster instead of back out the bug and redo the release properly.

            Time and money and lack of interest in the end customer experience due to the captive audience.

    2. UnknownUnknown

      I think the word is hotch-patch, not hot-patch with the shite coming out of Microsoft these days.

      No QA & Agile AI Coding = this.

  2. Bran Muffin

    Linux Security Roundup for Week 11, 2026 Reveals Critical Fixes

    "This week's Linux Security Roundup for Week 11, 2026 highlights several critical patches that demand immediate attention from system administrators and desktop users alike. The summary addresses flaws in major platforms that could impact daily operations if left unaddressed. Ignoring these updates leaves systems open to exploitation from known attack vectors that have already been documented by security researchers." [Emphasis is mine.]

    https://www.linuxcompatible.org/story/linux-security-roundup-for-week-11-2026/

    1. Carnotaurus

      Re: Linux Security Roundup for Week 11, 2026 Reveals Critical Fixes

      Downvotes are certainly the Linux fans who can't/won't accept their beloved penguins can also have bugs.

      1. RM Myers
        Unhappy

        Re: Linux Security Roundup for Week 11, 2026 Reveals Critical Fixes

        Fanbois vs fanbois vs fanbois. I go back to the days of IBM versus the 7 dwarfs, and who can forget the 8086 vs Z80 vs 6502 vs 68000 vs ... Then there was the Fortran vs Algol vs PL1 vs (the list goes on forever). The names change, the technologies change, but the arguing never ends. Can't we all just agree to disagree, and get on with life.

        Sigh!

        1. Zack Mollusc Silver badge

          Re: Linux Security Roundup for Week 11, 2026 Reveals Critical Fixes

          How are we supposed to get on with life when you missed out the 6809?

          1. RM Myers
            Thumb Up

            Re: Linux Security Roundup for Week 11, 2026 Reveals Critical Fixes

            Have an upvote for at least giving me a good laugh.

      2. Gavsky

        Re: Linux Security Roundup for Week 11, 2026 Reveals Critical Fixes

        Indeed, nobody's animal mascot is safe these days! Erm, or fruit...

      3. alisonken1
        FAIL

        Re: Linux Security Roundup for Week 11, 2026 Reveals Critical Fixes

        Actually, the downvotes are for trying to treat the updates as killers if not patched without context. And blaming the penguin for everything without noting that the critical updates are limited in scope and what needs patching.

        Fearmongering to point the finger at someone else to hide your insecurities is not a valid critique method.

      4. David Hicklin Silver badge

        Re: Linux Security Roundup for Week 11, 2026 Reveals Critical Fixes

        > Downvotes are certainly the Linux fans who can't/won't accept their beloved penguins can also have bugs

        Nah we fully accept it and I see updates/fixes arriving almost *daily* here in Linux Mint world.

        The downvotes (including mine) are for crowing about it on an article about Micro$lop patch issues.

    2. Steve Foster

      Re: Linux Security Roundup for Week 11, 2026 Reveals Critical Fixes

      I don't think anyone has claimed that Linux has reached perfection (or ever might).

      It's more the case that MS' legendary unwillingness to consider QC as anything other than a nuisance [at best] has continued to scale new heights. Which combined with their new determination to let "AI" write all their code unsupervised is proving to be demonstrably awful for a lot of folks who have the misfortune to have to use MS software.

      1. Strahd Ivarius Silver badge
        Trollface

        Re: Linux Security Roundup for Week 11, 2026 Reveals Critical Fixes

        "AI" (autonomous idiot) doesn't write all the code unsupervised at MS, it is writing only the part that requires emergency security fixes.

    3. Justin Pasher

      Re: Linux Security Roundup for Week 11, 2026 Reveals Critical Fixes

      While applying security patches in any context is important, you do realize the difference between Linux and applications that run on Linux, right? Windows is equivalent to the Linux kernel, not everything else that runs on it. Do you expect Microsoft to be held accountable for bugs in Adobe products?

      Yes, the Linux kernel still encounters security issues, like any piece of software, but at least they are not breaking the most basic of functionality on a regular basis.

      1. Anonymous Coward
        Anonymous Coward

        Re: Linux Security Roundup for Week 11, 2026 Reveals Critical Fixes

        Ehm no, Windows is equivalent to the Linux kernel + the filesystem + the hypervisor + the GUI system + the windows manager + the desktop manager + the user space utilities + a lot of libraries that are separate projects in Linux like OpenSSL... and probably I forgot something... it's not a kernel only.

        1. Anonymous Coward
          Anonymous Coward

          Re: Linux Security Roundup for Week 11, 2026 Reveals Critical Fixes

          I forgot systemd and all its services, of course....

          Plus the various network managers....

          1. Eric 9001

            Re: Linux Security Roundup for Week 11, 2026 Reveals Critical Fixes

            Many people don't use systemd, nor a network manager on their GNU/Linux install.

            I don't use systemd.

        2. Eric 9001
          Boffin

          Re: Linux Security Roundup for Week 11, 2026 Reveals Critical Fixes

          Linux is and will always be a kernel only, no matter how many people are confused and refer to software that has nothing to do with Linux as "Linux".

          This confusion is so bad that people seriously refer to Linux as "Linux kernel".

          In reality, the OS is GNU, as it's basically a GNU system, with Linux added, to make GNU/Linux (or you can add Hurd instead to make GNU/Hurd), which also supports a lot of other 3rd party software, which care a lot about interfacing with GNU libraries, but usually don't care about what kernel you use.

          openssl had nothing to do with Linux from the start - it was originally designed to use GNU's libraries and tooling to be portable across many Unix-like OS's.

          Inspecting the oldest version available; 0.9.6; https://openssl-library.org/source/old/0.9.x/ and browsing the files, the supported OS's are; Nextstep, NCR MP-RAS, NetBSD, "Free"BSD, "Open"BSD, QNX, UnixWare, IBM AIX, Cray, LynxOS, MPE/iX, A/UX, dgux, HI-UX, HP-UX, IRIX, OSF1, SunOS, ConvexOS, Unix System V, DYNIX/ptx, ULTRIX, SCO, ReliantUNIX, SINIX, BS2000-OSD, Windows, MacOS X, Sony NEWS-OS and of course GNU/Linux.

          To build, openssl needs GCC, GNU bc and perl and several other libraries and programs, but it doesn't particularly care what kernel you use.

          Still, the cool use gnuTLS instead.

          Correctly, Windows can only be compared to an GNU/Linux distro that has ¼ of the thousands of available packages installed by default.

    4. Roland6 Silver badge

      Re: Linux Security Roundup for Week 11, 2026 Reveals Critical Fixes

      So all planned, no “out of band “ fixes…

    5. Kevin McMurtrie Silver badge

      Re: Linux Security Roundup for Week 11, 2026 Reveals Critical Fixes

      This big Linux patch installed in about 6 seconds and didn't cause any interruption. It's an ordinary update of software packages that can be released and applied at any time. No restart, logout, or quitting apps is required for them. A new kernel arrived independently that will take effect on the next restart.

      I rarely see a Windows update that doesn't need a few minutes of downtime and a reboot. And then there's MacOS with its epic updating system.

      1. Anonymous Coward
        Anonymous Coward

        Re: Linux Security Roundup for Week 11, 2026 Reveals Critical Fixes

        Starnage, I had to reboot all my Ubuntu servers today.... because there was a kernel update...

      2. Anonymous Coward
        Anonymous Coward

        Re: Linux Security Roundup for Week 11, 2026 Reveals Critical Fixes

        Yes, it is actually surprising that MacOS (and some application) updates want a reboot unless it's just the security signatures for XProtect of Xcode updates. MacOS does have the facility to restart services without a full restart, but I'm guessing it's easier to do a restart to keep it all in sync.

        Which reminds me, I have to take a look at the Linux box :).

    6. Eric 9001
      Boffin

      Re: Linux Security Roundup for Week 11, 2026 Reveals Critical Fixes

      It's not a valid comparison to compare 2 fixed bugs in windows itself (you don't get a choice whether to have endless vulnerable components of windows you don't use installed) to many fixed security bugs of optionally-installed software in addition to the core GNU/Linux OS.

      Microsoft software seems to have 1000x the security vulnerabilities compared to GNU/Linux and also most the software available for GNU/Linux too.

      I don't have most of that software installed and many of the vulnerabilities seem to be DoS ones or not applicable.

      Meanwhile, if you are used by windows 11 and use bluetooth, it seems it was extremely likely for you to have (more) bluetooth connection problems and even if you don't use bluetooth, but the computer has a bluetooth card, the bluetooth vulnerability seems applicable.

      1. Anonymous Coward
        Anonymous Coward

        Re: Linux Security Roundup for Week 11, 2026 Reveals Critical Fixes

        Many of that "optionally installed" software delivers basic functionalities without which Linux would be useless. Or you mean you can run a Linux box today without, say, OpenSSH or Python?

        1. Eric 9001
          Boffin

          Re: Linux Security Roundup for Week 11, 2026 Reveals Critical Fixes

          You can run a GNU box and most GNU packages and a lot of other packages, perfectly well without many of the optional dependencies, such as python or openssh - as such programs are not relevant to many use cases.

          GNU/BusyBox/Linux distros like LibreCMC for example don't come with python or openssh - dropbear is used instead for ssh.

          Packages like GNU units, GNU Emacs, GNU nano, glibc, readline, gettext, gimp, patch, diffutils, GNU coreutils, ncurses, GNU sed, GNU awk, GNU tar, GNU grep, aspell etc are all critical packages to me, but for some, those packages are all optional dependencies.

    7. Jimjam3 Bronze badge

      Re: Linux Security Roundup for Week 11, 2026 Reveals Critical Fixes

      Interesting but why mention it in a post about Microsloft breaking Bluetooth ?

      Trolling anyone?

  3. TangoDelta72
    FAIL

    Thanks for reporting this, El Reg!

    I am on Win 11 Pro and was affected by this about a week ago, too. At the time, it was a new enough problem where not much was out there yet to research a fix. My MS-branded BT mouse wheel became effectively unusable (e.g. - scrolling up would result in a down scroll; sometimes a doc would just jump around because it sensed some wheel input). While a reboot would likely have helped me out, restarting the BT service is what fixed me [for the time being].

  4. Anonymous Coward
    Anonymous Coward

    In other news...

    According to unnamed sources, Bluetooth will be phased out and replaced by Redtooth in the glorious USoA as requested by their Supreme Leader, to better align with the Party colors (and also the tie).

    1. mirachu

      Re: In other news...

      How about Redbeard (Barbarossa)?

      1. Judge Mental
        Pint

        Re: In other news...

        I see what you did there.

    2. Anonymous Coward
      Anonymous Coward

      Re: In other news...

      Wasn't it OrangeFang?

  5. Gavsky

    Unfortunately, like "customer data exfiltrated from X company/organisation", "Microsoft releases update Y to fix issue caused by update X", is no news these days. A perfect case history for future IT professionals to shake their heads at: proper QC & testing can be expensive, but is really important.

  6. Dan 55 Silver badge

    It's an improvement

    Before I had to wait till the 2nd Tuesday of the month for my Bluetooth pairing to get screwed up, now it can go wrong much earlier.

  7. BPontius

    The rest of us

    When do the grunts that don't hot patch get the problem(s) fixed Microsoft?

    The rest of us would like to have these problems fixed also!

  8. Groo The Wanderer - A Canuck Silver badge

    Don't complain so much. The ads are getting through and the AI infestation continues unabated so everything is going to plan....

  9. Bebu sa Ware Silver badge
    Windows

    hotchpatch ?

    by analogy with hodgepodge which is arguably the MS stock in trade.

  10. Lee D Silver badge

    It's alright.

    I've spent the last couple of years making sure that all the staff at my workplace, and my bosses, know one thing:

    We are no longer in control of updates.

    It's that simple. If an update deploys in the middle of the day and breaks stuff? Nothing I can do. If an update chooses an inconvenient time and you can't defer it? Nothing I can do. If an update brings down the servers? Nothing I can do.

    There's plenty I can do about all the other stuff I deal with, but Windows Updates are no longer in my control, and they should know that.

    It rebooted at 9am right in the middle of your presentation? (shrug).

    Your machine took an hour to update last night while you needed to work? (shrug)

    Your machine keeps bugging you about rebooting but you don't want to because you're working? (shrug)

    Your machine deployed an update and now something doesn't work properly? (shrug)

    Patch Tuesday knocked out a dozen of our VM's? (shrug)

    I can restore from backup. I can reinstall. I can restart. I can hope for a hotfix. That's it.

    MS took the control away from me... so they can take the responsibility with it.

    I've been prepping my employers and all their employees for that. I think everyone else should too.

    And it applies to other things:

    MS took away a menu in Word? (shrug).

    They bundled Copilot into your file explorer? (shrug).

    It keeps trying to set Edge as default no matter how many times we tell it not to? (shrug)

    Teams/Outlook is now in bundled in Original, Ready Salted, (new), (new) (New), etc. versions and things don't work the same between them? (shrug)

    MS says your computer is obsolete and you need a new one to run Windows 11? (shrug)

    You decided this is the only OS you can use, and the manufacturers of that OS have imposed their requirements on you. Follow them. Because I, basically, can do nothing but fire-fighting on them and I get absolutely zero official assistance from them in doing so. Even gathering information, resources and solutions on ONE SUCH PROBLEM for today would take up all my time, and the solution would be "can't do that" and I'd only find that at the bottom of some third-party comments on an MS KB article as the most "prestigious" source, let alone the fact that the only real information and pointers to that would be spread across Reddit and a thousand other sites with other people like me similarly fire-fighting under pressure with no assistance.

    And most of the time? I can't say "yeah, I fixed that". Because next week... another Windows Update will land unannounced. And that'll change the browser default silently. And I look like a fool. So... no... I'm not going to say that I've fixed it. I'm going to tell the truth. Microsoft keep breaking it. There's nothing I can do.

    Honestly... MS are talking themselves out of being the dominant OS. It'll take years to happen, but that's what's going to happen. Because *I'm* more sick of it than I've ever been and I've just given up. It won't be long before users feel the same.

    1. Anonymous Coward
      Anonymous Coward

      Yes, I've noticed that our Corporate IT is reduced to saying they're "reaching out to" Microsoft whenever there's a problem, which probably means posting a message on their forums.

  11. Taliesinawen Bronze badge

    Hotpatching: the default for Windows Autopatch.

    Traditional Windows security updates typically require restarting for the changes to take effect. Hotpatching applies patches directly in memory to the running processes. These are not made permanent until the next quarterly baseline update cycle. Original binaries such as ntdll.dll, kernelbase.dll remain unchanged on disk. A reboot is required for the new disk files to be loaded into memory as the running baseline.

    1. Lee D Silver badge

      Re: Hotpatching: the default for Windows Autopatch.

      Yeah, a technique that's been in use since the 60's and has had at least three iterations on Linux to my knowledge (and I really don't follow it).

      Everything from the "Linux kernel trampoline" patches to... 2.0? Or was it 2.2? upwards.

      You just make things modular, switch out the syscalls to the new kernel's syscalls, and keep track of who's using the old vs new syscalls, while making sure that newly-started processes only use the new ones.

      It's incredibly tricky and fragile but it can be done.

      The problem is... it can also be abused, and if it's done badly your entire server is now more fragile.

  12. running with nukes
    Pint

    AI removes BT

    El Reg recently posted a slew of articles about BSOD [blue screen of death] in the wild. In response, Microsoft AI was assigned the task of removing BSOD from Windows 11.

    The closest code match found was for something called Bluetooth. Easy peezy

  13. Steve B

    Now I understand why/

    As an old OS developer, I could never understand how these systems got out with "vulnerabilities" to be discovered each day.

    We were one of the first to use a high level language to write an OS, under the mistaken belief that being a higher level meant that there was a vast amount of talent who could be used to do the job.

    We quickly learnt that was not the case and you still needed good programmers to keep the product credible,

    I was told IBM overcame the obstacle by not allowing their developers to write anything that went over one listing page.

    Fast Forward to PCs, IBM and MS coupled with no lessons learnt and we end up with US generated OSs developed using high level languages by people who don't understand why the programs should work first time (That's why they developed Agile?).

    I just watched a youtube vid on hacking a bespoke box and now I can see why there are such issues.

    The whole security issue seems to be down to a couple of simple issues such as:-

    Inept developers using a higher level language for ease of development resulting in:-

    There is no data validation;

    unknown strings are passed as commands to the parsers etc.

    All covered on week two of the programmers course back in the day!

    Our implemented ideas were so much better with code only allowed into code memory segments which were then, after initial load, unable to be modified. In store Data was held in data only memory and the hardware would not process the data as code under any circumstances.

    It might have been slightly more regimented but it was effective.

    What is even stranger is that it was all achieved by UK hardware and software developers under imported US Directors who at the successful end of their contracts left to return home, bringing back the inept British School Tie qualified directors who rapidly ran the company back into the ground.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon