{"id":"CVE-2026-19571","summary":"Race condition in ITE IT8xxx2 SHI host-command backend lets a second SPI request write an unvalidated length into the in-flight request buffer","details":"The ITE IT8xxx2 SHI host-command backend (subsys/mgmt/ec_host_cmd/backends/ec_host_cmd_backend_shi_ite.c) copied the 8-byte host-command request header from the SPI Rx FIFO directly into the shared receive buffer data-\u003ein_msg and only afterwards checked the protocol version and the derived packet length. The interrupt handler also accepted a chip-select assertion and an Rx-valid-length (RVLI) interrupt in any driver state other than SHI_STATE_DISABLED, so a new header could be parsed while the host-command thread was still processing the previous request out of the very same buffer.\n\nThe host processor is the SPI controller and drives both chip select and the clock. After sending a well-formed request it can immediately de-assert chip select — which returns the driver to the ready state and re-enables the FIFO — and start a second transaction carrying a header with data_len = 0xFFFF. Those eight bytes are written into in_msg before the oversized length is rejected, so they land in a buffer whose contents verify_rx() in subsys/mgmt/ec_host_cmd/ec_host_cmd_handler.c has already validated. If this lands in the window before the host-command thread executes args.input_buf_size = rx_header-\u003edata_len, the framework hands the registered command handler a 65535-byte input length over a 256-byte buffer.\n\nThe result is an out-of-bounds read of up to roughly 64 KiB beyond the request buffer: command handlers that copy or echo input_buf_size bytes disclose adjacent embedded-controller memory back to the host or overflow the response buffer, and a read past the end of SRAM faults the controller. The same race also allows cmd_id and cmd_ver to be swapped after checksum verification and after handler lookup. Exploitation requires the ability to drive the inter-processor SHI bus (a compromised host OS or physical access to the SPI lines) and winning a timing race, which the SPI controller can retry indefinitely.\n\nThe fix parses the header into a local struct ec_host_cmd_request_header and copies it into in_msg only after the length has been bounded by sizeof(data-\u003ein_msg), and ignores chip-select and RVLI interrupts outside SHI_STATE_READY_TO_RECV/SHI_STATE_RECEIVING. A residual, bounded race remains: an end-of-transaction interrupt still resets the state to ready while the host-command thread owns the buffer, so a valid second request can still overwrite the in-flight request's contents, unlike the NPCX backend which parks in SHI_STATE_CNL_RESP_NOT_RDY while the buffer is in use.","aliases":["GHSA-4x98-6536-cwjv"],"modified":"2026-10-11T07:04:32.502704426Z","published":"2026-10-09T07:16:40.717Z","database_specific":{"cna_assigner":"zephyr","cwe_ids":["CWE-362"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19571.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"3.3.0"},{"fixed":"4.5.0"}]}]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19571.json"},{"type":"ADVISORY","url":"https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-4x98-6536-cwjv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19571"},{"type":"FIX","url":"https://github.com/zephyrproject-rtos/zephyr/commit/0636e65c825e810ad97f154606365870152d402f"},{"type":"PACKAGE","url":"https://github.com/zephyrproject-rtos/zephyr"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/zephyrproject-rtos/zephyr","events":[{"introduced":"0"},{"fixed":"0636e65c825e810ad97f154606365870152d402f"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v4.4.0","v4.4.0-rc3","v4.4.0-rc2","v4.4.0-rc1","v4.3.0","v4.3.0-rc3","v4.3.0-rc2","v4.3.0-rc1","v4.2.0","v4.2.0-rc3","v4.2.0-rc2","v4.2.0-rc1","v4.1.0","v4.1.0-rc3","v4.1.0-rc2","v4.1.0-rc1","v4.0.0","v4.0.0-rc3","v4.0.0-rc2","v4.0.0-rc1","v3.7.0","v3.7.0-rc3","v3.7.0-rc2","v3.7.0-rc1","v3.6.0","v3.6.0-rc3","v3.6.0-rc2","v3.6.0-rc1","zephyr-v3.5.0","v3.5.0","v3.5.0-rc3","v3.5.0-rc2","v3.5.0-rc1","zephyr-v3.4.0","v3.4.0","v3.4.0-rc3","v3.4.0-rc2","v3.4.0-rc1","zephyr-v3.3.0","v3.3.0","v3.3.0-rc3","v3.3.0-rc2","v3.3.0-rc1","zephyr-v3.2.0","v3.2.0","v3.2.0-rc3","v3.2.0-rc2","v3.2.0-rc1","zephyr-v3.1.0","v3.1.0","v3.1.0-rc3","v3.1.0-rc2","v3.1.0-rc1","zephyr-v3.0.0","v3.0.0","v3.0.0-rc3","v3.0.0-rc2","v3.0.0-rc1","v2.7.99","v2.7.0-rc3","v2.7.0-rc2","v2.7.0-rc1","zephyr-v2.6.0","v2.6.0","v2.6.0-rc3","v2.6.0-rc2","v2.6.0-rc1","zephyr-v2.5.0","v2.5.0","v2.5.0-rc4","v2.5.0-rc3","v2.5.0-rc2","v2.5.0-rc1","zephyr-v2.4.0","v2.4.0","v2.4.0-rc3","v2.4.0-rc2","v2.4.0-rc1","zephyr-v2.3.0","v2.3.0","v2.3.0-rc2","v2.3.0-rc1","zephyr-v2.1.0","v2.1.0","zephyr-v2.2.0","v2.2.0","v2.2.0-rc3","v2.2.0-rc2","v2.2.0-rc1","v2.1.0-rc3","v2.1.0-rc2","v2.1.0-rc1","zephyr-v2.0.0","v2.0.0","v2.0.0-rc3","v2.0.0-rc2","v2.0.0-rc1","zephyr-v1.14.0","v1.14.0","v1.14.0-rc3","v1.14.0-rc2","v1.14.0-rc1","zephyr-v1.13.0","v1.13.0","v1.13.0-rc3","v1.13.0-rc2","v1.13.0-rc1","zephyr-v1.12.0","v1.12.0","v1.12.0-rc3","v1.12.0-rc2","v1.12.0-rc1","zephyr-v1.11.0","v1.11.0","v1.11.0-rc3","v1.11.0-rc2","v1.11.0-rc1","zephyr-v1.10.0","v1.10.0","v1.10.0-rc3","v1.10.0-rc2","v1.10.0-rc1","zephyr-v1.9.0","v1.9.0","v1.9.0-rc4","v1.9.0-rc3","v1.9.0-rc2","v1.9.0-rc1","v1.8.99","zephyr-v1.5.0","v1.5.0","v1.7.99","v1.6.99","v1.5.0-rc4","v1.5.0-rc3","v1.5.0-rc2","v1.5.0-rc1","v1.5.0-rc0","zephyr-v1.4.0","v1.4.0","v1.4.0-rc3","v1.4.0-rc2","v1.4.0-rc1","zephyr-v1.3.0","v1.3.0","v1.3.0-rc2","v1.3.0-rc1","zephyr-v1.2.0","v1.2.0","v1.2.0-rc2","v1.2.0-rc1","zephyr-v1.1.0","v1.1.0","v1.1.0-rc1","zephyr-v1.0.0","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19571.json","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["17089197368196677691686540596279999615","198732158950289187689888601725567873965","246519463278990683942323508430048583157","316891566195549983531061119856616954214","270987785083536966133283351132623655588","307094727395447310719568704071199085582","287957361407341228784000147638457568995","94998054934186890308531446164358221617","294154092106142623671576611109242498361","78096371024564122274387938468893439594","339258749036494518101552946962728793597","289322162760448209757201423259706342607","177044087880180975265617508109405733641","244404874830259595287080035928432705722","280508970745340978019817638921362965476","47966867862614466726505161751392257685","134138266485428720161893492451094743092","29957759092861402748112660125661991725","237938730689873282163119474636040790985","297389932272112511848492995334282630268","54237316222802962549888792130948008383","44717709696660590978181665432799776789","144143613735407238527637716019313993765","306001052500062614977097084483679370977","316631141434779598373837835815994403518"],"threshold":0.9},"id":"CVE-2026-19571-16f32a74","signature_type":"Line","signature_version":"v1","source":"https://github.com/zephyrproject-rtos/zephyr/commit/0636e65c825e810ad97f154606365870152d402f","target":{"file":"subsys/mgmt/ec_host_cmd/backends/ec_host_cmd_backend_shi_ite.c"}}],"vanir_signatures_modified":"2026-10-11T07:04:32Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H"}]}