Description
The ITE it82xx2 USB device-controller driver initialized its bus-suspend detection work with k_work_init_delayable(&priv->suspended_work, suspended_handler) inside it82xx2_enable() (the driver's .enable op) in drivers/usb/udc/udc_it82xx2.c. This work item is scheduled essentially continuously while the USB bus is active: the interrupt handler reschedules it on every SOF frame and suspended_handler() reschedules itself, so its timeout node is normally linked in the kernel timeout list / a workqueue pending queue.

k_work_init_delayable() (kernel/work.c) unconditionally overwrites the entire k_work_delayable structure, including its timeout and queue linkage, with no busy check. Because it82xx2_disable() does not cancel the work, a normal disable-then-enable cycle re-runs api->enable() (udc_enable() only rejects a redundant enable, not a re-enable after disable) and re-initializes the still-pending work in place, corrupting the kernel timeout/workqueue linked lists and causing a kernel panic.

An external USB host — for example a host performing USB DFU detach (dfu-util --detach) or forcing repeated attach/reset/re-enumeration — drives the udc_disable()/udc_enable() transitions and controls suspend/resume timing, so it can arrange for the suspend work to be pending across a re-enable. This yields an unauthenticated denial of service (kernel panic) reachable across the USB boundary from a removable, physically-connected host, with no confidentiality or integrity impact demonstrated.

The fix moves the k_work_init_delayable() call into the one-time preinit function so the work is initialized exactly once, eliminating the re-initialization of an in-use item.
Published: 2026-09-14
Score: 4.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service: kernel panic via USB bus operations
Action: Apply Patch
AI Analysis

Impact

The driver for the ITE it82xx2 USB device controller re‑initializes a delayable work item whenever the controller is enabled. Because the work item is already queued when the controller is disabled and then re‑enabled, the kernel overwrites its timeout and queue links, corrupting the timeout and workqueue lists. The corruption triggers a kernel panic, resulting in an unauthenticated denial of service. No confidentiality or integrity impact has been demonstrated.

Affected Systems

Zephyr RTOS builds that include the drivers/usb/udc/udc_it82xx2.c component for ITE it82xx2 USB device controllers. All hardware implementations using that driver, regardless of specific OTA firmware version, may be affected.

Risk and Exploitability

The CVSS score of 4.6 indicates moderate severity. The EPSS score is less than 1%, which suggests a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, implying limited publicly documented exploitation. The attack can be conducted by an external USB host that triggers detach or repeated attach events, such as a DFU utility or power cycling. Because the exploit does not require authentication on the host side and only requires physical USB access, the risk is accessible to any attacker with physical connectivity to the target device.

Generated by OpenCVE AI on September 20, 2026 at 22:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Zephyr to a version that contains commit 350fd5dfd, which moves the delayable work item initialization to a one‑time pre‑initialization function, eliminating the dangerous re‑initialization.
  • If an update is not immediately possible, configure the system or host firmware to avoid repeated USB detach/attach cycles during operation, ensuring that enable/disable transitions do not occur while a suspend work item is pending.
  • Enable logging or monitoring for kernel panic events caused by USB suspend handlers so that any interruption can be detected quickly.

Generated by OpenCVE AI on September 20, 2026 at 22:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Zephyrproject
Zephyrproject zephyr
Vendors & Products Zephyrproject
Zephyrproject zephyr

Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description The ITE it82xx2 USB device-controller driver initialized its bus-suspend detection work with k_work_init_delayable(&priv->suspended_work, suspended_handler) inside it82xx2_enable() (the driver's .enable op) in drivers/usb/udc/udc_it82xx2.c. This work item is scheduled essentially continuously while the USB bus is active: the interrupt handler reschedules it on every SOF frame and suspended_handler() reschedules itself, so its timeout node is normally linked in the kernel timeout list / a workqueue pending queue. k_work_init_delayable() (kernel/work.c) unconditionally overwrites the entire k_work_delayable structure, including its timeout and queue linkage, with no busy check. Because it82xx2_disable() does not cancel the work, a normal disable-then-enable cycle re-runs api->enable() (udc_enable() only rejects a redundant enable, not a re-enable after disable) and re-initializes the still-pending work in place, corrupting the kernel timeout/workqueue linked lists and causing a kernel panic. An external USB host — for example a host performing USB DFU detach (dfu-util --detach) or forcing repeated attach/reset/re-enumeration — drives the udc_disable()/udc_enable() transitions and controls suspend/resume timing, so it can arrange for the suspend work to be pending across a re-enable. This yields an unauthenticated denial of service (kernel panic) reachable across the USB boundary from a removable, physically-connected host, with no confidentiality or integrity impact demonstrated. The fix moves the k_work_init_delayable() call into the one-time preinit function so the work is initialized exactly once, eliminating the re-initialization of an in-use item.
Title Kernel panic in the it82xx2 USB device controller driver via re-initialization of a busy delayable work item
Weaknesses CWE-666
References
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Zephyrproject Zephyr
cve-icon MITRE

Status: PUBLISHED

Assigner: zephyr

Published:

Updated: 2026-09-14T20:06:36.377Z

Reserved: 2026-07-17T18:21:32.752Z

Link: CVE-2026-16148

cve-icon Vulnrichment

Updated: 2026-09-14T20:06:30.943Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T20:16:39.360

Modified: 2026-09-14T21:10:41.650

Link: CVE-2026-16148

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:45:05Z

Weaknesses
  • CWE-666

    Operation on Resource in Wrong Phase of Lifetime