Answer in brief
CVE-2026-80771 records a Unknown severity vulnerability in HID: nintendo: register input device after capabilities are set. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=2af16c1f846bd60240745bbd3afa13d5f040c61a <3288bec1a21d582b504344380139cdc0e88ebe4d || >=2af16c1f846bd60240745bbd3afa13d5f040c61a <268679f501386ad46405d42c2bcf89384cb5e256 || >=2af16c1f846bd60240745bbd3afa13d5f040c61a <a9fc7547f911ada09da33c5e204e5acda38e765a || >=2af16c1f846bd60240745bbd3afa13d5f040c61a <27dc4b8eadac73b3c3cc526c8547d8b4ae8528be || >=2af16c1f846bd60240745bbd3afa13d5f040c61a <d723bc1fe2e72b9252234e94c11af644ec477bf7 | 3288bec1a21d582b504344380139cdc0e88ebe4d, 268679f501386ad46405d42c2bcf89384cb5e256, a9fc7547f911ada09da33c5e204e5acda38e765a, 27dc4b8eadac73b3c3cc526c8547d8b4ae8528be, d723bc1fe2e72b9252234e94c11af644ec477bf7 |
| Linux/Linuxgeneric | 5.16 | Not reported |
Published upstream
Sep 4, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 4, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 4, 2026
In the Linux kernel, the following vulnerability has been resolved: HID: nintendo: register input device after capabilities are set input_register_device() exposes the device to userspace immediately. In joycon_input_create() it was called before joycon_config_rumble() configures the FF_RUMBLE capability and the memless force-feedback device, so a concurrent EVIOCSFF could dereference a NULL dev->ff. Registering early also means the initial udev event lacks button and axis information, which can make input managers ignore the device. Move input_register_device() to the end of joycon_input_create(), after all capabilities, the IMU input device and the force-feedback callbacks have been configured.
Quoted source text, attributed separately from HOL analysis.