Out-of-Bounds Read Vulnerability in ITE IT8xxx2 SHI Host Command Backend
CVE-2026-19571
What is CVE-2026-19571?
The ITE IT8xxx2 SHI host-command backend contains a vulnerability that allows an attacker to exploit a race condition leading to out-of-bounds reading. The issue arises when the backend processes host-command requests, as it copies a request header into a shared receive buffer without adequately validating the packet length. If a second request is initiated before the first one is fully processed, it can cause a buffer overflow. This vulnerability can leak sensitive memory or cause system faults, depending on how the command handlers are implemented. Exploitation requires access to the SHI bus, which can be achieved through a compromised host operating system or direct access to the SPI lines. The recommended fix enforces proper validation of the request header length and manages interrupt states more effectively to mitigate this risk.
Affected Version(s)
zephyr 3.3.0 < 4.5.0
