Back

HIGH

HID: nintendo: fix rumble worker null pointer deref

Published Jun 18, 2025

Description

We can dereference a null pointer trying to queue work to a destroyed workqueue.

If the device is disconnected, nintendo_hid_remove is called, in which the rumble_queue is destroyed. Avoid using that queue to defer rumble work once the controller state is set to JOYCON_CTLR_STATE_REMOVED.

This eliminates the null pointer dereference.

Affected products

Remediation

No remediation recorded yet.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Jun 18, 2025
Updated Aug 15, 2026
Reserved Jun 18, 2025
NVD
Status Modified
Modified Aug 15, 2026
Red Hat
Severity Moderate
Public date Jun 18, 2025
ENISA EUVD
Assigner Linux
Published Jun 18, 2025
Updated Aug 15, 2026
Exploited since n/a
EUVD-2022-55254