HID: nintendo: register input device after capabilities are set
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.2%
exploitation probability
0.2%top 94% of all CVEs
observed exploitation
nono source reports it
In the Linux kernel, the following vulnerability has been resolved:
HID: nintendo: register input device after capabilities are set
input_register_device() exposes the device to userspace immediately.
In joycon_input_create() it was called before joycon_config_rumble()
configures the FF_RUMBLE capability and the memless force-feedback
device, so a concurrent EVIOCSFF could dereference a NULL dev->ff.
Registering early also means the initial udev event lacks button and
axis information, which can make input managers ignore the device.
Move input_register_device() to the end of joycon_input_create(), after
all capabilities, the IMU input device and the force-feedback callbacks
have been configured.
Affected products
Linux · LinuxReferences
https://git.kernel.org/stable/c/268679f501386ad46405d42c2bcf89384cb5e256https://git.kernel.org/stable/c/27dc4b8eadac73b3c3cc526c8547d8b4ae8528behttps://git.kernel.org/stable/c/3288bec1a21d582b504344380139cdc0e88ebe4dhttps://git.kernel.org/stable/c/a9fc7547f911ada09da33c5e204e5acda38e765ahttps://git.kernel.org/stable/c/d723bc1fe2e72b9252234e94c11af644ec477bf7