USB Device-Controller Driver Vulnerability in ITE Products
CVE-2026-16148

4.6MEDIUM

Key Information:

Status
Vendor
CVE Published:
14 September 2026

What is CVE-2026-16148?

The it82xx2 USB device-controller driver contains a flaw in its bus-suspend detection mechanism, potentially leading to a denial of service. Specifically, the initialization process of the suspend work item is flawed, allowing it to be continuously re-scheduled while USB activity persists. This mismanagement can result in a situation where re-enabling the driver after a disabled state causes a kernel panic due to corrupted work queue structures. Unauthorized USB hosts can exploit this vulnerability by manipulating suspend/resume timing, leading to crashes that disrupt system stability.

Affected Version(s)

zephyr 3.7.0 < 4.4.2

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.