Memory Corruption Vulnerability in NXP MCUX TRNG Driver
CVE-2026-19736
7.8HIGH
What is CVE-2026-19736?
A vulnerability in the NXP MCUX TRNG entropy driver could lead to memory corruption by allowing malicious user mode threads to manipulate memory beyond the bounds of their allocated space. This occurs when the driver passes the caller's specified byte count directly to a vendor SDK routine without adequate checks, particularly when non-word-multiple lengths are requested. As a result, uncontrolled data can overwrite sensitive kernel memory areas, potentially leading to crashes, unpredictable system behavior, or privilege escalation. The issue primarily affects devices using specific configurations of the MCUX SDK that enable TRNG_SW_HEALTH_TESTS.
Affected Version(s)
zephyr 4.3.0 <= 4.4.2
