Memory Corruption Vulnerability in NXP MCUX TRNG Driver
CVE-2026-19736

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
11 October 2026

What is CVE-2026-19736?

A vulnerability in the NXP MCUX TRNG entropy driver could lead to memory corruption by allowing malicious user mode threads to manipulate memory beyond the bounds of their allocated space. This occurs when the driver passes the caller's specified byte count directly to a vendor SDK routine without adequate checks, particularly when non-word-multiple lengths are requested. As a result, uncontrolled data can overwrite sensitive kernel memory areas, potentially leading to crashes, unpredictable system behavior, or privilege escalation. The issue primarily affects devices using specific configurations of the MCUX SDK that enable TRNG_SW_HEALTH_TESTS.

Affected Version(s)

zephyr 4.3.0 <= 4.4.2

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.