Impact
The driver for the ITE it82xx2 USB device controller re‑initializes a delayable work item whenever the controller is enabled. Because the work item is already queued when the controller is disabled and then re‑enabled, the kernel overwrites its timeout and queue links, corrupting the timeout and workqueue lists. The corruption triggers a kernel panic, resulting in an unauthenticated denial of service. No confidentiality or integrity impact has been demonstrated.
Affected Systems
Zephyr RTOS builds that include the drivers/usb/udc/udc_it82xx2.c component for ITE it82xx2 USB device controllers. All hardware implementations using that driver, regardless of specific OTA firmware version, may be affected.
Risk and Exploitability
The CVSS score of 4.6 indicates moderate severity. The EPSS score is less than 1%, which suggests a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, implying limited publicly documented exploitation. The attack can be conducted by an external USB host that triggers detach or repeated attach events, such as a DFU utility or power cycling. Because the exploit does not require authentication on the host side and only requires physical USB access, the risk is accessible to any attacker with physical connectivity to the target device.
OpenCVE Enrichment