Description
The ITE IT82xx2 USB device-controller driver (drivers/usb/udc/udc_it82xx2.c) mishandles multi-packet OUT transfers on non-control endpoints. In work_handler_out() the active transfer buffer is obtained with udc_buf_peek() (which does not dequeue it); when a full max-packet-size packet arrives but the buffer still has tailroom (the transfer is not yet complete), the pre-fix code both re-arms the endpoint to keep filling that same buf via work_handler_xfer_continue() and simultaneously hands the same, still-being-filled buffer to the upper stack with udc_submit_ep_event().

Because udc_submit_ep_event() transfers ownership of the buffer to the USB device stack (usbd_event_carrier() appends &buf->node to uds_ctx->ep_events, after which the class handler processes and net_buf_unref()s it), the driver continues to DMA subsequent host-controlled OUT packets into a buffer the upper stack may already have freed and recycled — a use-after-free write. In addition, since the buffer was never dequeued, the completing packet runs udc_buf_get() on the same object and submits it a second time, appending &buf->node to the event slist twice (singly-linked-list corruption) and causing a double net_buf_unref().

The IT82xx2 is a USB peripheral controller, so the untrusted USB host controls OUT-transfer packetization and can force this path against any non-control OUT endpoint whose queued buffer exceeds one packet — an ordinary bulk/interrupt pattern. The driver and USB device stack run in kernel context above the external host, giving the host a device-side kernel heap-corruption primitive: a reliable denial of service and, because the written bytes are attacker-controlled, plausible corruption of adjacent net_buf pool memory. The vector is physical (USB attach). The fix defers submission until the buffer is completely filled and lets xfer_work_handler() drive continuation, so each OUT buffer is submitted to the upper stack exactly once.
Published: 2026-09-14
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Use-After-Free with Kernel Heap Corruption
Action: Patch Immediately
AI Analysis

Impact

The IT82xx2 USB device‑controller driver mishandles multi‑packet OUT transfers, leading to a use‑after‑free write when the same buffer is handed over to the USB stack before it is fully consumed. This flaw also corrupts a singly‑linked event list. The resulting kernel heap corruption can be triggered with attacker‑controlled data and causes a reliable denial of service.

Affected Systems

All builds of Zephyr that include the IT82xx2 driver are potentially affected; no specific version ranges are listed, so any commit prior to the fix should be considered vulnerable. The referenced commit 2abc3088 implements the required change.

Risk and Exploitability

With a CVSS score of 6.8 and an EPSS score of 0.00182 (0.18%), the vulnerability is considered moderate to high severity. The attack vector is physical: a USB host that can send arbitrary OUT packets to non‑control endpoints. The kernel context of the driver gives the host a direct path to manipulate kernel memory, enabling both denial of service and potential arbitrary memory corruption. The vulnerability is not currently tracked in CISA KEV, but its exploitation is straightforward once an attacker can supply fragmented OUT packets.

Generated by OpenCVE AI on September 20, 2026 at 23:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Zephyr to a version that includes the commit 2abc3088 or later, which defers buffer submission until fully filled.
  • Restrict USB host access to trusted devices or disable USB connectivity during critical operations to prevent an attacker from delivering the malformed OUT packets.
  • Add defensive checks in the driver to ensure that a buffer has been fully consumed and not recently freed before passing ownership to the USB stack; this mitigates future similar use‑after‑free attempts.

Generated by OpenCVE AI on September 20, 2026 at 23:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Zephyrproject
Zephyrproject zephyr
Vendors & Products Zephyrproject
Zephyrproject zephyr

Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description The ITE IT82xx2 USB device-controller driver (drivers/usb/udc/udc_it82xx2.c) mishandles multi-packet OUT transfers on non-control endpoints. In work_handler_out() the active transfer buffer is obtained with udc_buf_peek() (which does not dequeue it); when a full max-packet-size packet arrives but the buffer still has tailroom (the transfer is not yet complete), the pre-fix code both re-arms the endpoint to keep filling that same buf via work_handler_xfer_continue() and simultaneously hands the same, still-being-filled buffer to the upper stack with udc_submit_ep_event(). Because udc_submit_ep_event() transfers ownership of the buffer to the USB device stack (usbd_event_carrier() appends &buf->node to uds_ctx->ep_events, after which the class handler processes and net_buf_unref()s it), the driver continues to DMA subsequent host-controlled OUT packets into a buffer the upper stack may already have freed and recycled — a use-after-free write. In addition, since the buffer was never dequeued, the completing packet runs udc_buf_get() on the same object and submits it a second time, appending &buf->node to the event slist twice (singly-linked-list corruption) and causing a double net_buf_unref(). The IT82xx2 is a USB peripheral controller, so the untrusted USB host controls OUT-transfer packetization and can force this path against any non-control OUT endpoint whose queued buffer exceeds one packet — an ordinary bulk/interrupt pattern. The driver and USB device stack run in kernel context above the external host, giving the host a device-side kernel heap-corruption primitive: a reliable denial of service and, because the written bytes are attacker-controlled, plausible corruption of adjacent net_buf pool memory. The vector is physical (USB attach). The fix defers submission until the buffer is completely filled and lets xfer_work_handler() drive continuation, so each OUT buffer is submitted to the upper stack exactly once.
Title it82xx2 USB device controller submits incomplete OUT transfer buffers, causing use-after-free and event-list corruption
Weaknesses CWE-416
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Zephyrproject Zephyr
cve-icon MITRE

Status: PUBLISHED

Assigner: zephyr

Published:

Updated: 2026-09-14T20:05:14.713Z

Reserved: 2026-07-17T18:21:31.577Z

Link: CVE-2026-16147

cve-icon Vulnrichment

Updated: 2026-09-14T20:05:07.641Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T20:16:39.207

Modified: 2026-09-14T21:10:41.650

Link: CVE-2026-16147

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:30:07Z

Weaknesses