Junglewise Threat Intelligence

CVE-2026-16148: ITE it82xx2 USB device-controller driver work item re-initialization denial of service

CVE-2026-16148 · Severity: medium · CVSS 4.6 · Published 2026-09-14

Executive brief

The ITE it82xx2 USB device controller driver, used to handle USB communications on embedded systems, contains a flaw in how it manages background worker processes. When a USB host repeatedly connects and disconnects (or uses USB firmware update sequences), the driver reinitializes an active background task without properly stopping it first, corrupting kernel data structures. This causes the system kernel to crash, resulting in a complete device outage that can be triggered by any external USB device without authentication.

Technical details

The vulnerability is a use-after-free / data structure corruption in the ITE it82xx2 UDC driver (drivers/usb/udc/udc_it82xx2.c). The driver initializes a delayed work item (suspended_work) within the .enable() callback using k_work_init_delayable(), which unconditionally overwrites the work structure including active linkage in the kernel timeout and workqueue lists. When a USB host triggers a disable-then-enable cycle (via DFU detach, repeated enumeration, or suspend/resume transitions), the .enable() callback re-invokes k_work_init_delayable() on a work item that may still be pending in the kernel's internal queues, corrupting linked list pointers and causing a kernel panic. The attack vector is network-adjacent (physically connected USB) with no authentication required; the precondition is a USB host capable of forcing device-controller transitions. The fix relocates the initialization to a one-time preinit function to ensure it runs exactly once.

Affected products

  • ITE it82xx2 USB device-controller driver <UNKNOWN>

Timeline

  • 2026-09-14: disclosed

Related threats