---
id: CVE-2026-14986
title: >-
  The ITE it51xxx I2C driver, when operating as an I2C target (slave) in buffer
  mode (CONFIG_I2C_TARGET + CONFIG_I2C_TARGET_BUFFER_MODE), copies host-supplied
  write data into the fixed-size data->target_in_buffer inside its target FIFO
  int…
summary: >-
  The ITE it51xxx I2C driver, when operating as an I2C target (slave) in buffer
  mode (CONFIG_I2C_TARGET + CONFIG_I2C_TARGET_BUFFER_MODE), copies host-supplied
  write data into the fixed-size data->target_in_buffer inside its target FIFO
  int…
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-787
vendor: zephyrproject
product: zephyr
affected:
  - zephyr >= 4.2.0 < 4.4.2
published: '2026-09-14'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:11:57.760'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-14986'
references:
  - url: >-
      https://github.com/zephyrproject-rtos/zephyr/commit/eac92173cf13bba4e6c6eea3460ee6085513d86d
    label: vulnerabilities@zephyrproject.org
  - url: >-
      https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-jmjj-w736-fw2j
    label: vulnerabilities@zephyrproject.org
tags:
  - nvd
  - cve.org
epss: 0.00182
epssPercentile: 0.06947
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-15T13:42:52.993721Z'
ingestedAt: '2026-09-14T23:17:06.521Z'
---

## Overview

The ITE it51xxx I2C driver, when operating as an I2C target (slave) in buffer mode (CONFIG_I2C_TARGET + CONFIG_I2C_TARGET_BUFFER_MODE), copies host-supplied write data into the fixed-size data->target_in_buffer inside its target FIFO interrupt handler target_i2c_isr_fifo() in drivers/i2c/i2c_ite_it51xxx.c. The copy loop stores to target_in_buffer[i + data->w_index] and only checks data->w_index against sizeof(data->target_in_buffer) after the write has already completed, so the bounds check cannot prevent the overflow.

The running index data->w_index accumulates count bytes on every FIFO-fill interrupt of an ongoing transaction and is reset to zero only on a STOP or timeout condition. An I2C host that streams a single write transaction longer than the buffer (default CONFIG_I2C_TARGET_IT51XXX_MAX_BUF_SIZE = 256 bytes) drives data->w_index past the end of the buffer, and each subsequent host byte is written out of bounds into the adjacent data->target_out_buffer and following static device data.

The trigger is a malicious or misbehaving I2C master on the same bus (for example a compromised application processor or a rogue device on an exposed I2C bus); no software privilege on the victim is required and the handler runs in the target's kernel/firmware context. Because both the written values and the overflow length are attacker-controlled, this is an out-of-bounds write that can crash the controller or be shaped toward code execution. The fix adds a pre-write bounds check in target_i2c_fifo_read_to_buf() that aborts and resets the FIFO before any out-of-bounds store.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
