CVE-2026-14986 | ZephyrProject Zephyr up to 4.4.1 I2C Target Driver i2c_ite_it51xxx.c target_i2c_isr_fifo w_index out-of-bounds write

SecurityVulns

A vulnerability categorized as very critical has been discovered in ZephyrProject Zephyr up to 4.4.1. Affected by this issue is the function target_i2c_isr_fifo of the file drivers/i2c/i2c_ite_it51xxx.c of the component I2C Target Driver. The manipulation of the argument w_index results in out-of-bounds write.

This vulnerability is identified as CVE-2026-14986. The attack is only possible with local access. There is not any exploit available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More