All of lore.kernel.org
 help / color / mirror / Atom feed
* CVE-2026-80772: HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler()
@ 2026-09-04 15:11 Greg Kroah-Hartman
  0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-09-04 15:11 UTC (permalink / raw)
  To: linux-cve-announce; +Cc: Greg Kroah-Hartman

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler()

joycon_ctlr_read_handler() casts an incoming HID input report to
struct joycon_input_report and parses it, guarding the cast only with a
12-byte length check:

	if (size >= 12) /* make sure it contains the input report */
		joycon_parse_report(ctlr, (struct joycon_input_report *)data);

struct joycon_input_report is 49 bytes: a 13-byte header followed by a
union whose IMU arm is 36 bytes. For an IMU report joycon_parse_report()
-> joycon_parse_imu_report() walks that union (struct offsets 13..48),
so a report of exactly 12 bytes with data[0] == JC_INPUT_IMU_DATA passes
the guard yet is read up to 37 bytes past its declared length. The
over-read bytes are decoded into accelerometer/gyroscope values and
forwarded to userspace through the "(IMU)" input device, leaking
driver-internal memory. data[0] and size are fully controlled by a
malicious or spoofed Joy-Con/Pro Controller.

Receive buffers are sized to the maximum report length, so this is an
over-read within the allocation rather than a slab OOB, but the decoded
bytes still reach userspace.

The sibling subcmd path in joycon_ctlr_handle_event() already bounds the
same cast correctly:

	if (size < sizeof(struct joycon_input_report) ||
	    data[0] != JC_INPUT_SUBCMD_REPLY)
		break;

Use the same sizeof(struct joycon_input_report) bound here.

The Linux kernel CVE team has assigned CVE-2026-80772 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 5.16 with commit 2af16c1f846bd60240745bbd3afa13d5f040c61a and fixed in 6.1.185 with commit 33ea29f8b6141f2d265de807e110a6435b355cb0
	Issue introduced in 5.16 with commit 2af16c1f846bd60240745bbd3afa13d5f040c61a and fixed in 6.6.154 with commit bd397c4123a4bc084913d8c7fdb40ef94e9f8172
	Issue introduced in 5.16 with commit 2af16c1f846bd60240745bbd3afa13d5f040c61a and fixed in 6.12.106 with commit addca61f9a23c0d20a387c2040e70479f54518e1
	Issue introduced in 5.16 with commit 2af16c1f846bd60240745bbd3afa13d5f040c61a and fixed in 6.18.47 with commit 51cfd1adbe7a46bb08af162abb3ab3b6820e2d15
	Issue introduced in 5.16 with commit 2af16c1f846bd60240745bbd3afa13d5f040c61a and fixed in 7.1.11 with commit d4cabd4089adb59cf7974915737c52cc47a9bb1b
	Issue introduced in 5.16 with commit 2af16c1f846bd60240745bbd3afa13d5f040c61a and fixed in 7.2.1 with commit 34725ed4719da424113db8449fb5485aaf71a913
	Issue introduced in 5.16 with commit 2af16c1f846bd60240745bbd3afa13d5f040c61a and fixed in 7.3-rc1 with commit 27b376b945c0aac46fcdfcc950b14a85b874b557

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-80772
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	drivers/hid/hid-nintendo.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/33ea29f8b6141f2d265de807e110a6435b355cb0
	https://git.kernel.org/stable/c/bd397c4123a4bc084913d8c7fdb40ef94e9f8172
	https://git.kernel.org/stable/c/addca61f9a23c0d20a387c2040e70479f54518e1
	https://git.kernel.org/stable/c/51cfd1adbe7a46bb08af162abb3ab3b6820e2d15
	https://git.kernel.org/stable/c/d4cabd4089adb59cf7974915737c52cc47a9bb1b
	https://git.kernel.org/stable/c/34725ed4719da424113db8449fb5485aaf71a913
	https://git.kernel.org/stable/c/27b376b945c0aac46fcdfcc950b14a85b874b557

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-09-04 15:14 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-04 15:11 CVE-2026-80772: HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler() Greg Kroah-Hartman

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.