-

CVE-2026-80771

Medienbericht

HID: nintendo: register input device after capabilities are set

In the Linux kernel, the following vulnerability has been resolved:

HID: nintendo: register input device after capabilities are set

input_register_device() exposes the device to userspace immediately.
In joycon_input_create() it was called before joycon_config_rumble()
configures the FF_RUMBLE capability and the memless force-feedback
device, so a concurrent EVIOCSFF could dereference a NULL dev->ff.

Registering early also means the initial udev event lacks button and
axis information, which can make input managers ignore the device.

Move input_register_device() to the end of joycon_input_create(), after
all capabilities, the IMU input device and the force-feedback callbacks
have been configured.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 2af16c1f846bd60240745bbd3afa13d5f040c61a
Version < 3288bec1a21d582b504344380139cdc0e88ebe4d
Status affected
Version 2af16c1f846bd60240745bbd3afa13d5f040c61a
Version < 268679f501386ad46405d42c2bcf89384cb5e256
Status affected
Version 2af16c1f846bd60240745bbd3afa13d5f040c61a
Version < a9fc7547f911ada09da33c5e204e5acda38e765a
Status affected
Version 2af16c1f846bd60240745bbd3afa13d5f040c61a
Version < 27dc4b8eadac73b3c3cc526c8547d8b4ae8528be
Status affected
Version 2af16c1f846bd60240745bbd3afa13d5f040c61a
Version < d723bc1fe2e72b9252234e94c11af644ec477bf7
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.16
Status affected
Version 0
Version < 5.16
Status unaffected
Version <= 6.12.*
Version 6.12.106
Status unaffected
Version <= 6.18.*
Version 6.18.47
Status unaffected
Version <= 7.1.*
Version 7.1.11
Status unaffected
Version <= 7.2.*
Version 7.2.1
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.063
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
08.09.2026 20:38
https://git.kernel.org/stable/c/3288bec1a21d582b504344380139cdc0e88ebe4d
https://git.kernel.org/stable/c/268679f501386ad46405d42c2bcf89384cb5e256
https://git.kernel.org/stable/c/a9fc7547f911ada09da33c5e204e5acda38e765a
https://git.kernel.org/stable/c/27dc4b8eadac73b3c3cc526c8547d8b4ae8528be
https://git.kernel.org/stable/c/d723bc1fe2e72b9252234e94c11af644ec477bf7