Description
The ITE it51xxx I2C driver, when operating as an I2C target (slave) in buffer mode (CONFIG_I2C_TARGET + CONFIG_I2C_TARGET_BUFFER_MODE), copies host-supplied write data into the fixed-size data->target_in_buffer inside its target FIFO interrupt handler target_i2c_isr_fifo() in drivers/i2c/i2c_ite_it51xxx.c. The copy loop stores to target_in_buffer[i + data->w_index] and only checks data->w_index against sizeof(data->target_in_buffer) after the write has already completed, so the bounds check cannot prevent the overflow.

The running index data->w_index accumulates count bytes on every FIFO-fill interrupt of an ongoing transaction and is reset to zero only on a STOP or timeout condition. An I2C host that streams a single write transaction longer than the buffer (default CONFIG_I2C_TARGET_IT51XXX_MAX_BUF_SIZE = 256 bytes) drives data->w_index past the end of the buffer, and each subsequent host byte is written out of bounds into the adjacent data->target_out_buffer and following static device data.

The trigger is a malicious or misbehaving I2C master on the same bus (for example a compromised application processor or a rogue device on an exposed I2C bus); no software privilege on the victim is required and the handler runs in the target's kernel/firmware context. Because both the written values and the overflow length are attacker-controlled, this is an out-of-bounds write that can crash the controller or be shaped toward code execution. The fix adds a pre-write bounds check in target_i2c_fifo_read_to_buf() that aborts and resets the FIFO before any out-of-bounds store.
Published: 2026-09-14
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-Bounds Write Leading to Potential Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The ITE it51xxx I2C driver implements I2C target mode by copying master write data into a fixed-size buffer inside a FIFO interrupt handler. The driver omits a bounds check before copying, so the write may exceed the buffer boundary when the host streams a transaction longer than the default 256 bytes. Because the data and the overflow length are controlled by the I2C master, the flaw is an out‑of‑bounds write that can corrupt adjacent memory and, in a privileged kernel or firmware context, may crash the controller or lead to code execution. This vulnerability is categorized as CWE‑787.

Affected Systems

The flaw is present in the Zephyr RTOS source for the ITE it51 activated when CONFIG_I2C_TARGET and CONFIG_I2C_TARGET target feature on the it51xxx controller, whether in production or development, are vulnerable. The defect applies to all Zephyr releases that contain the unpatched driver code, including the code base referenced by the advisory.

Risk and Exploitability

The CVSS score for the vulnerability is 6.8, indicating medium severity. The EPSS score < 1% indicates a very low but non-zero likelihood of exploitation. The exploit vector is likely local to the device, requiring a malicious or misbehaving I2C master on the same bus. No privilege escalation is needed; the fault occurs in the driver running in the target’s privileged context. The vulnerability is not listed in the CISA KEV catalog, which suggests no widespread exploitation has been observed. An attacker with I2C bus access could stream a long write transaction to trigger the overflow and potentially achieve denial of service or remote code execution.

Generated by OpenCVE AI on September 17, 2026 at 19:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Zephyr to a version that includes the bound‑check patch (commit eac92173cf13bba4e6c6eea3460ee6085513d86d) or apply the patch manually to drivers/i2c/i2c_ite_it51xxx.c.
  • Disable CONFIG_I2C_TARGET and CONFIG if the device never operates as an I2C target.
  • If target with CONFIG_I2C_TARGET_IT51XXX_MAX_BUF_SIZE to a value that matches the maximum expected transaction length.

Generated by OpenCVE AI on September 17, 2026 at 19:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
First Time appeared Zephyrproject
Zephyrproject zephyr
Vendors & Products Zephyrproject
Zephyrproject zephyr

Mon, 14 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Description The ITE it51xxx I2C driver, when operating as an I2C target (slave) in buffer mode (CONFIG_I2C_TARGET + CONFIG_I2C_TARGET_BUFFER_MODE), copies host-supplied write data into the fixed-size data->target_in_buffer inside its target FIFO interrupt handler target_i2c_isr_fifo() in drivers/i2c/i2c_ite_it51xxx.c. The copy loop stores to target_in_buffer[i + data->w_index] and only checks data->w_index against sizeof(data->target_in_buffer) after the write has already completed, so the bounds check cannot prevent the overflow. The running index data->w_index accumulates count bytes on every FIFO-fill interrupt of an ongoing transaction and is reset to zero only on a STOP or timeout condition. An I2C host that streams a single write transaction longer than the buffer (default CONFIG_I2C_TARGET_IT51XXX_MAX_BUF_SIZE = 256 bytes) drives data->w_index past the end of the buffer, and each subsequent host byte is written out of bounds into the adjacent data->target_out_buffer and following static device data. The trigger is a malicious or misbehaving I2C master on the same bus (for example a compromised application processor or a rogue device on an exposed I2C bus); no software privilege on the victim is required and the handler runs in the target's kernel/firmware context. Because both the written values and the overflow length are attacker-controlled, this is an out-of-bounds write that can crash the controller or be shaped toward code execution. The fix adds a pre-write bounds check in target_i2c_fifo_read_to_buf() that aborts and resets the FIFO before any out-of-bounds store.
Title Out-of-bounds write in it51xxx I2C target FIFO ISR on oversized write transaction
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Zephyrproject Zephyr
cve-icon MITRE

Status: PUBLISHED

Assigner: zephyr

Published:

Updated: 2026-09-15T13:43:00.316Z

Reserved: 2026-07-07T18:24:46.814Z

Link: CVE-2026-14986

cve-icon Vulnrichment

Updated: 2026-09-15T13:42:57.372Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T23:17:15.533

Modified: 2026-09-18T19:11:57.760

Link: CVE-2026-14986

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:30:18Z

Weaknesses