Impact
The IT82xx2 USB device‑controller driver mishandles multi‑packet OUT transfers, leading to a use‑after‑free write when the same buffer is handed over to the USB stack before it is fully consumed. This flaw also corrupts a singly‑linked event list. The resulting kernel heap corruption can be triggered with attacker‑controlled data and causes a reliable denial of service.
Affected Systems
All builds of Zephyr that include the IT82xx2 driver are potentially affected; no specific version ranges are listed, so any commit prior to the fix should be considered vulnerable. The referenced commit 2abc3088 implements the required change.
Risk and Exploitability
With a CVSS score of 6.8 and an EPSS score of 0.00182 (0.18%), the vulnerability is considered moderate to high severity. The attack vector is physical: a USB host that can send arbitrary OUT packets to non‑control endpoints. The kernel context of the driver gives the host a direct path to manipulate kernel memory, enabling both denial of service and potential arbitrary memory corruption. The vulnerability is not currently tracked in CISA KEV, but its exploitation is straightforward once an attacker can supply fragmented OUT packets.
OpenCVE Enrichment