HID: nintendo: stop device IO before hid_hw_stop on probe failure
Summary
| CVE | CVE-2026-80770 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-04 16:18:02 UTC |
| Updated | 2026-09-04 16:18:02 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: HID: nintendo: stop device IO before hid_hw_stop on probe failure nintendo_hid_probe() calls hid_device_io_start() before joycon_init() and joycon_leds_create(). If either fails, the error path jumps to err_close which calls hid_hw_close()/hid_hw_stop() without first calling hid_device_io_stop(). hid_hw_stop() does not stop device IO, so hid_input_report() may still run and access driver data that is being torn down, resulting in a use-after-free. Add an err_io_stop label that calls hid_device_io_stop() before hid_hw_close(), and point the two post-io_start error paths at it. |
Risk And Classification
EPSS: 0.001730000 probability, percentile 0.068290000 (date 2026-09-07)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 2af16c1f846bd60240745bbd3afa13d5f040c61a c2f3d51c7f5222f5b51e0c90f02258d82e1b44dd git | Not specified |
| CNA | Linux | Linux | affected 2af16c1f846bd60240745bbd3afa13d5f040c61a c023443f0e6cfd257846b6515c93c1ea08026593 git | Not specified |
| CNA | Linux | Linux | affected 2af16c1f846bd60240745bbd3afa13d5f040c61a 03a84f9f88b42cd49752ec0259922b67e4b88598 git | Not specified |
| CNA | Linux | Linux | affected 2af16c1f846bd60240745bbd3afa13d5f040c61a 5efcd7bbfaaec67d137c99aa0940fa34375db27f git | Not specified |
| CNA | Linux | Linux | affected 2af16c1f846bd60240745bbd3afa13d5f040c61a 13a3edf96568a0b7aacadea07c2adec53ac8f630 git | Not specified |
| CNA | Linux | Linux | affected 2af16c1f846bd60240745bbd3afa13d5f040c61a 2e0d98dc8a6dea5fc2b72bf66e0dcbd5488644b4 git | Not specified |
| CNA | Linux | Linux | affected 2af16c1f846bd60240745bbd3afa13d5f040c61a 1f74d3bff6fe04a64e02ab3661d2e0d554565aa6 git | Not specified |
| CNA | Linux | Linux | affected 5.16 | Not specified |
| CNA | Linux | Linux | unaffected 5.16 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.187 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.156 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.106 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.47 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.1.11 7.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2.1 7.2.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.3-rc1 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/03a84f9f88b42cd49752ec0259922b67e4b88598 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/2e0d98dc8a6dea5fc2b72bf66e0dcbd5488644b4 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/c2f3d51c7f5222f5b51e0c90f02258d82e1b44dd | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/1f74d3bff6fe04a64e02ab3661d2e0d554565aa6 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/13a3edf96568a0b7aacadea07c2adec53ac8f630 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/c023443f0e6cfd257846b6515c93c1ea08026593 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/5efcd7bbfaaec67d137c99aa0940fa34375db27f | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.