PT-2026-91746 · Ite · It51Xxx I2C Driver
CVE-2026-14986
·
Published
2026-09-14
·
Updated
2026-09-15
CVSS v3.1
6.8
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ITE it51xxx I2C driver (affected versions not specified)
Description
An out-of-bounds write exists when the driver operates as an I2C target in buffer mode. The issue occurs within the
target i2c isr fifo() interrupt handler in drivers/i2c/i2c ite it51xxx.c, where host-supplied write data is copied into the fixed-size data->target in buffer. Because the bounds check for the data->w index variable is performed only after the write operation completes, a malicious or misbehaving I2C master can stream a transaction exceeding the buffer size (default 256 bytes). This allows the attacker to overwrite the adjacent data->target out buffer and subsequent static device data. Since the handler runs in the kernel or firmware context, this can lead to a system crash or arbitrary code execution.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
It51Xxx I2C Driver