Junglewise Threat Intelligence

CVE-2026-14986: ITE it51xxx I2C driver buffer overflow in target FIFO handler

CVE-2026-14986 · Severity: medium · CVSS 6.8 · Published 2026-09-14

Executive brief

The ITE it51xxx I2C driver, used in embedded controllers and microcontrollers to manage I2C communication, contains a buffer overflow vulnerability when operating in I2C target (slave) mode. A malicious or misbehaving device on the same I2C bus can send a long data stream that overflows an internal buffer and overwrites adjacent memory, potentially crashing the controller or enabling code execution without requiring any software privileges on the victim.

Technical details

This is a classic out-of-bounds write vulnerability in the I2C target FIFO interrupt handler (target_i2c_isr_fifo() in drivers/i2c/i2c_ite_it51xxx.c). When CONFIG_I2C_TARGET and CONFIG_I2C_TARGET_BUFFER_MODE are enabled, the driver copies host-supplied write data into a fixed-size buffer (target_in_buffer, default 256 bytes), but the bounds check is performed after the write completes rather than before, making it ineffective. The running index (data->w_index) accumulates across multiple FIFO-fill interrupts during a single I2C transaction and is only reset on STOP or timeout. An attacker on the I2C bus can stream a write transaction longer than the buffer size, causing data->w_index to exceed buffer bounds and subsequent writes to overflow into the adjacent target_out_buffer and other static device memory. Since both the written values and overflow length are attacker-controlled, this enables a shaped out-of-bounds write attack. The fix adds a pre-write bounds check that aborts and resets the FIFO before any overflow occurs.

Affected products

  • ITE it51xxx I2C driver unspecified

Timeline

  • 2026-09-14: disclosed