SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-80770

UNKNOWN · CVSS N/A EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-19

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's handling of Nintendo Joy-Con controllers, specifically during the initialization process where device I/O is not properly stopped before the hardware is closed. This oversight can lead to a use-after-free condition, potentially allowing unauthorized access to driver data during teardown. Organizations using Linux systems that interface with Nintendo devices should prioritize addressing this issue to mitigate the risk of exploitation.

CVE
CVE-2026-80770
Severity
UNKNOWN
CVSS
N/A
EPSS
0.17%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: HID: nintendo: stop device IO before hid_hw_stop on probe failure nintendo_hid_probe() calls hid_device_io_start() before joycon_init() and joycon_leds_create(). If either fails, the error path jumps to err_close which calls hid_hw_close()/hid_hw_stop() without first calling hid_device_io_stop(). hid_hw_stop() does not stop device IO, so hid_input_report() may still run and access driver data that is being torn down, resulting in a use-after-free. Add an err_io_stop label that calls hid_device_io_stop() before hid_hw_close(), and point the two post-io_start error paths at it.