USB Device-Controller Driver Vulnerability in ITE Products
CVE-2026-16148
4.6MEDIUM
What is CVE-2026-16148?
The it82xx2 USB device-controller driver contains a flaw in its bus-suspend detection mechanism, potentially leading to a denial of service. Specifically, the initialization process of the suspend work item is flawed, allowing it to be continuously re-scheduled while USB activity persists. This mismanagement can result in a situation where re-enabling the driver after a disabled state causes a kernel panic due to corrupted work queue structures. Unauthorized USB hosts can exploit this vulnerability by manipulating suspend/resume timing, leading to crashes that disrupt system stability.
Affected Version(s)
zephyr 3.7.0 < 4.4.2
