目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-19571— ITE IT8xxx2 SPI竞争条件漏洞

一分钟漏洞结论

影响对象
zephyrproject zephyr
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

ITE IT8xxx2 SHI(Host Command Interface)后端驱动(位于 )存在安全漏洞。该驱动将来自 SPI 接收 FIFO 的 8 字节主机命令请求头直接复制到共享接收缓冲区 中,随后才检查协议版本和推导出的数据包长度。此外,中断处理程序在除 (禁用状态)之外的任何驱动状态下,都会接受芯片选择(chip-select)断言和接收有效长度(RVLI)中断。因此,当主机命令线程仍在从同一缓冲区处理前一个请求时,就可能解析新的请求头。 SPI 控制器作为主机处理器,同时驱动芯片选择和时钟信号。在发

CVSS 6.7 · Medium
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-19571 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Race condition in ITE IT8xxx2 SHI host-command backend lets a second SPI request write an unvalidated length into the in-flight request buffer
来源: CVE Program / CVE List V5
Vulnerability Description
The ITE IT8xxx2 SHI host-command backend (subsys/mgmt/ec_host_cmd/backends/ec_host_cmd_backend_shi_ite.c) copied the 8-byte host-command request header from the SPI Rx FIFO directly into the shared receive buffer data->in_msg and only afterwards checked the protocol version and the derived packet length. The interrupt handler also accepted a chip-select assertion and an Rx-valid-length (RVLI) interrupt in any driver state other than SHI_STATE_DISABLED, so a new header could be parsed while the host-command thread was still processing the previous request out of the very same buffer. The host processor is the SPI controller and drives both chip select and the clock. After sending a well-formed request it can immediately de-assert chip select — which returns the driver to the ready state and re-enables the FIFO — and start a second transaction carrying a header with data_len = 0xFFFF. Those eight bytes are written into in_msg before the oversized length is rejected, so they land in a buffer whose contents verify_rx() in subsys/mgmt/ec_host_cmd/ec_host_cmd_handler.c has already validated. If this lands in the window before the host-command thread executes args.input_buf_size = rx_header->data_len, the framework hands the registered command handler a 65535-byte input length over a 256-byte buffer. The result is an out-of-bounds read of up to roughly 64 KiB beyond the request buffer: command handlers that copy or echo input_buf_size bytes disclose adjacent embedded-controller memory back to the host or overflow the response buffer, and a read past the end of SRAM faults the controller. The same race also allows cmd_id and cmd_ver to be swapped after checksum verification and after handler lookup. Exploitation requires the ability to drive the inter-processor SHI bus (a compromised host OS or physical access to the SPI lines) and winning a timing race, which the SPI controller can retry indefinitely. The fix parses the header into a local struct ec_host_cmd_request_header and copies it into in_msg only after the length has been bounded by sizeof(data->in_msg), and ignores chip-select and RVLI interrupts outside SHI_STATE_READY_TO_RECV/SHI_STATE_RECEIVING. A residual, bounded race remains: an end-of-transaction interrupt still resets the state to ready while the host-command thread owns the buffer, so a valid second request can still overwrite the in-flight request's contents, unlike the NPCX backend which parks in SHI_STATE_CNL_RESP_NOT_RDY while the buffer is in use.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
使用共享资源的并发执行不恰当同步问题(竞争条件)
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
zephyrproject zephyr 3.3.0 ~ 4.5.0 -

二、漏洞 CVE-2026-19571 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-19571 的情报信息

请登录查看更多情报信息。

CVE-2026-19571 其他参考 (2)

同批安全公告 · zephyrproject · 2026-10-09 · 共 5 条

CVE-2026-19570 8.8 HIGH LE Audio广播接收端越界写入漏洞
CVE-2026-19569 8.8 HIGH 动态内核对象分配的整型溢出导致内核堆被破坏
CVE-2026-19575 7.8 HIGH 设备去初始化系统调用类型混淆可导致远程代码执行漏洞
CVE-2026-19574 7.0 HIGH ARM64 MMU内存域分配漏洞导致用户模式内存隔离失效

IV. Related Vulnerabilities

V. Comments for CVE-2026-19571

暂无评论


发表评论