CVE-2026-19571 | ZephyrProject Zephyr up to 4.4.x ITE IT8xxx2 SHI host-command backend ec_host_cmd_backend_shi_ite.c verify_rx data_len out-of-bounds
A vulnerability classified as problematic was found in ZephyrProject Zephyr up to 4.4.x. Affected is the function verify_rx of the file subsys/mgmt/ec_host_cmd/backends/ec_host_cmd_backend_shi_ite.c of the component ITE IT8xxx2 SHI host-command backend. Executing a manipulation of the argument data_len can lead to out-of-bounds read.
The identification of this vulnerability is CVE-2026-19571. The attack can only be executed locally. There is no exploit available.
Upgrading the affected component is advised.VulDB Recent EntriesRead More