PT-2026-91746 · Ite · It51Xxx I2C Driver

CVE-2026-14986

·

Published

2026-09-14

·

Updated

2026-09-15

CVSS v3.1

6.8

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ITE it51xxx I2C driver (affected versions not specified)
Description An out-of-bounds write exists when the driver operates as an I2C target in buffer mode. The issue occurs within the target i2c isr fifo() interrupt handler in drivers/i2c/i2c ite it51xxx.c, where host-supplied write data is copied into the fixed-size data->target in buffer. Because the bounds check for the data->w index variable is performed only after the write operation completes, a malicious or misbehaving I2C master can stream a transaction exceeding the buffer size (default 256 bytes). This allows the attacker to overwrite the adjacent data->target out buffer and subsequent static device data. Since the handler runs in the kernel or firmware context, this can lead to a system crash or arbitrary code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14986
GHSA-JMJJ-W736-FW2J

Affected Products

It51Xxx I2C Driver