Answer in brief
CVE-2026-80770 records a Unknown severity vulnerability in HID: nintendo: stop device IO before hid_hw_stop on probe failure. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=2af16c1f846bd60240745bbd3afa13d5f040c61a <c2f3d51c7f5222f5b51e0c90f02258d82e1b44dd || >=2af16c1f846bd60240745bbd3afa13d5f040c61a <c023443f0e6cfd257846b6515c93c1ea08026593 || >=2af16c1f846bd60240745bbd3afa13d5f040c61a <03a84f9f88b42cd49752ec0259922b67e4b88598 || >=2af16c1f846bd60240745bbd3afa13d5f040c61a <5efcd7bbfaaec67d137c99aa0940fa34375db27f || >=2af16c1f846bd60240745bbd3afa13d5f040c61a <13a3edf96568a0b7aacadea07c2adec53ac8f630 || >=2af16c1f846bd60240745bbd3afa13d5f040c61a <2e0d98dc8a6dea5fc2b72bf66e0dcbd5488644b4 || >=2af16c1f846bd60240745bbd3afa13d5f040c61a <1f74d3bff6fe04a64e02ab3661d2e0d554565aa6 | c2f3d51c7f5222f5b51e0c90f02258d82e1b44dd, c023443f0e6cfd257846b6515c93c1ea08026593, 03a84f9f88b42cd49752ec0259922b67e4b88598, 5efcd7bbfaaec67d137c99aa0940fa34375db27f, 13a3edf96568a0b7aacadea07c2adec53ac8f630, 2e0d98dc8a6dea5fc2b72bf66e0dcbd5488644b4, 1f74d3bff6fe04a64e02ab3661d2e0d554565aa6 |
| Linux/Linuxgeneric | 5.16 | Not reported |
Published upstream
Sep 4, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 4, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 4, 2026
In the Linux kernel, the following vulnerability has been resolved: HID: nintendo: stop device IO before hid_hw_stop on probe failure nintendo_hid_probe() calls hid_device_io_start() before joycon_init() and joycon_leds_create(). If either fails, the error path jumps to err_close which calls hid_hw_close()/hid_hw_stop() without first calling hid_device_io_stop(). hid_hw_stop() does not stop device IO, so hid_input_report() may still run and access driver data that is being torn down, resulting in a use-after-free. Add an err_io_stop label that calls hid_device_io_stop() before hid_hw_close(), and point the two post-io_start error paths at it.
Quoted source text, attributed separately from HOL analysis.