Impact
The Linux kernel’s HID Nintendo driver registers an input device before fully configuring its force‑feedback capabilities. When a user process simultaneously issues an EVIOCSFF ioctl, the driver may dereference a null dev->ff pointer, causing a kernel crash. This flaw can be exploited to crash the kernel, resulting in a denial‑of‑service condition for the affected system.
Affected Systems
The vulnerability exists in the Linux kernel, specifically the HID Nintendo driver. Any kernel build containing the unpatched HID Nintendo code path is impacted. Systems running recent kernels will receive the fix via the forthcoming kernel update.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in CISA KEV. The CVSS score is not provided, but the described null pointer dereference in a kernel driver indicates high severity. The vulnerability requires local interaction with a JoyCon device during creation; a privileged or local user can trigger a system crash or reboot, causing denial of service.
OpenCVE Enrichment
Debian DLA