# CVE-2026-14986 — zephyrproject zephyr

> As of 2026-09-15, CVE-2026-14986 is a MEDIUM-severity vulnerability in zephyrproject zephyr, CVSS v3.1 6.8, EPSS 0.1% (8.0th percentile). No Threadlinqs-tracked threat campaign has been attributed to CVE-2026-14986 as of 2026-09-15; the identifier is re-checked against the Threadlinqs threat corpus on every daily ingest.

**Last updated:** 2026-09-15

## What is CVE-2026-14986?

The ITE it51xxx I2C driver, when operating as an I2C target (slave) in buffer mode (CONFIG_I2C_TARGET + CONFIG_I2C_TARGET_BUFFER_MODE), copies host-supplied write data into the fixed-size data->target_in_buffer inside its target FIFO interrupt handler target_i2c_isr_fifo() in drivers/i2c/i2c_ite_it51xxx.c. The copy loop stores to target_in_buffer[i + data->w_index] and only checks data->w_index against sizeof(data->target_in_buffer) after the write has already completed, so the bounds check cannot prevent the overflow. The running index data->w_index accumulates count bytes on every FIFO-fill interrupt of an ongoing transaction and is reset to zero only on a STOP or timeout condition. An I2C host that streams a single write transaction longer than the buffer (default CONFIG_I2C_TARGET_IT51XXX_MAX_BUF_SIZE = 256 bytes) drives data->w_index past the end of the buffer, and each subsequent host byte is written out of bounds into the adjacent data->target_out_buffer and following static device data. The trigger is a malicious or misbehaving I2C master on the same bus (for example a compromised application processor or a rogue device on an exposed I2C bus); no software privilege on the victim is required and the handler runs in the target's kernel/firmware context. Because both the written values and the overflow length are attacker-controlled, this is an out-of-bounds write that can crash the controller or be shaped toward code execution. The fix adds a pre-write bounds check in target_i2c_fifo_read_to_buf() that aborts and resets the FIFO before any out-of-bounds store.

The record classifies CVE-2026-14986 under weakness class [CWE-787](https://intel.threadlinqs.com/cwe/CWE-787). Its CVSS v3 base vector states that the flaw requires physical access to the device, needs no prior authentication, needs no user interaction, and has high impact on confidentiality, integrity, availability. 1 affected-product entry is recorded, across 1 vendor, listed below. The identifier was first published 21 days ago.

## Severity and exploitation probability

- **CVSS v3.1 base score:** 6.8 — MEDIUM (`CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H`)
- **EPSS (FIRST):** 0.1% probability of exploitation in the next 30 days, higher than 8.0% of all scored CVEs
- **CISA KEV:** Not listed in the CISA Known Exploited Vulnerabilities catalog
- **Threadlinqs priority:** 3.7/10 — a Threadlinqs composite of the CVSS base score, the EPSS percentile and public exploit availability
- **Published:** 2026-09-14, last modified 2026-09-15

## Is CVE-2026-14986 being exploited?

It currently carries a trending score of 32 in the Threadlinqs vulnerability feed.

## Affected products and versions

- [zephyrproject](https://intel.threadlinqs.com/vendors/zephyrproject): zephyr

## How to fix CVE-2026-14986

No vendor patch reference has been recorded for CVE-2026-14986 in the tracked sources. Follow the references below for a fix, and treat the products listed above as exposed until the vendor states otherwise.

## Threat activity tracking CVE-2026-14986

No threat campaign in the Threadlinqs corpus currently references CVE-2026-14986, in its CVE list or as an indicator. The linkage is recomputed from the live corpus on every daily ingest, so this section fills in as soon as a tracked campaign cites the identifier.

## Sources

Enriched from CVE.org, NVD, FIRST EPSS. Last verified by Threadlinqs on 2026-09-15. This product uses the NVD API but is not endorsed or certified by the NVD.

**Vendor advisory and patch**

- [github.com — patch](https://github.com/zephyrproject-rtos/zephyr/commit/eac92173cf13bba4e6c6eea3460ee6085513d86d)

**Other references**

- [github.com](https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-jmjj-w736-fw2j)

Canonical: https://intel.threadlinqs.com/cve/CVE-2026-14986
Full detection coverage and IOCs for threats exploiting CVE-2026-14986 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
