Impact
The ITE it51xxx I2C driver implements I2C target mode by copying master write data into a fixed-size buffer inside a FIFO interrupt handler. The driver omits a bounds check before copying, so the write may exceed the buffer boundary when the host streams a transaction longer than the default 256 bytes. Because the data and the overflow length are controlled by the I2C master, the flaw is an out‑of‑bounds write that can corrupt adjacent memory and, in a privileged kernel or firmware context, may crash the controller or lead to code execution. This vulnerability is categorized as CWE‑787.
Affected Systems
The flaw is present in the Zephyr RTOS source for the ITE it51 activated when CONFIG_I2C_TARGET and CONFIG_I2C_TARGET target feature on the it51xxx controller, whether in production or development, are vulnerable. The defect applies to all Zephyr releases that contain the unpatched driver code, including the code base referenced by the advisory.
Risk and Exploitability
The CVSS score for the vulnerability is 6.8, indicating medium severity. The EPSS score < 1% indicates a very low but non-zero likelihood of exploitation. The exploit vector is likely local to the device, requiring a malicious or misbehaving I2C master on the same bus. No privilege escalation is needed; the fault occurs in the driver running in the target’s privileged context. The vulnerability is not listed in the CISA KEV catalog, which suggests no widespread exploitation has been observed. An attacker with I2C bus access could stream a long write transaction to trigger the overflow and potentially achieve denial of service or remote code execution.
OpenCVE Enrichment