Out-of-Bounds Read Vulnerability in ITE IT8xxx2 SHI Host Command Backend
CVE-2026-19571

6.7MEDIUM

Key Information:

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-19571?

The ITE IT8xxx2 SHI host-command backend contains a vulnerability that allows an attacker to exploit a race condition leading to out-of-bounds reading. The issue arises when the backend processes host-command requests, as it copies a request header into a shared receive buffer without adequately validating the packet length. If a second request is initiated before the first one is fully processed, it can cause a buffer overflow. This vulnerability can leak sensitive memory or cause system faults, depending on how the command handlers are implemented. Exploitation requires access to the SHI bus, which can be achieved through a compromised host operating system or direct access to the SPI lines. The recommended fix enforces proper validation of the request header length and manages interrupt states more effectively to mitigate this risk.

Affected Version(s)

zephyr 3.3.0 < 4.5.0

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.