CVE-2022-49974 Information

Description

In the Linux kernel the following vulnerability has been resolved:

HID: nintendo: fix rumble worker null pointer deref

We can dereference a null pointer trying to queue work to a destroyed workqueue.

If the device is disconnected nintendo_hid_remove is called in which the rumble_queue is destroyed. Avoid using that queue to defer rumble work once the controller state is set to JOYCON_CTLR_STATE_REMOVED.

This eliminates the null pointer dereference.

Reference

https://git.kernel.org/stable/c/1ff89e06c2e5fab30274e4b02360d4241d6e605e https://git.kernel.org/stable/c/7c6e6c334154be16740b44dcd7638fb510b9bd91

CNNVD-202506-2261 (Published: 2025-06-18)

Share on: