Executive brief
The ITE IT82xx2 USB controller is a hardware device that handles USB data transfers in embedded systems. A flaw in its driver allows a malicious USB device connected to a system to trigger memory corruption in the kernel, potentially causing system crashes or unpredictable behavior. The vulnerability is triggered simply by plugging in the malicious device—no user action required.
Technical details
The vulnerability is a use-after-free bug in the IT82xx2 USB device-controller driver (drivers/usb/udc/udc_it82xx2.c) occurring in multi-packet OUT transfers on non-control endpoints. When a full max-packet-size packet arrives but the buffer has remaining space, the driver both re-arms the endpoint to continue filling the buffer and simultaneously submits that buffer to the upper USB stack, which takes ownership and may free it. The driver then continues to DMA subsequent packets into the freed buffer and attempts to submit it a second time, causing singly-linked-list corruption and double-free. The attack vector is physical (USB attachment); an attacker controlling a USB device can force this condition against any bulk or interrupt OUT endpoint, gaining reliable kernel heap corruption and denial of service.
Affected products
- ITE IT82xx2 USB device-controller driver <unknown>
Timeline
- 2026-09-14: disclosed