CVE-2026-19736
Received Received - Intake

Buffer Overflow in NXP MCUX TRNG Entropy Driver

Vulnerability report for CVE-2026-19736, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: Zephyr Project

Description

The NXP MCUX TRNG entropy driver in drivers/entropy/entropy_mcux_trng.c passed the caller's byte count straight to the vendor SDK routine TRNG_GetRandomData(). On i.MX RT5xx and RT6xx parts the SDK compiles its TRNG_SW_HEALTH_TESTS variant, which always copies whole 32-bit words and draws entropy rounded up to a multiple of 128 bytes. Its "caller buffer is full" guard tests dataSize == 0, so a request whose length is not a multiple of four makes dataSize underflow past zero and the SDK keeps writing into the caller's buffer for the entire extraction: a 1-byte request results in 128 bytes written, and any non-word-multiple length overflows by up to 127 bytes. entropy_get_entropy() is a syscall, and its verifier in drivers/entropy/entropy_handlers.c validates only the requested length via K_SYSCALL_MEMORY_WRITE(). With CONFIG_USERSPACE enabled, an unprivileged user-mode thread that has merely been granted the entropy device can therefore choose both the destination address and a length such as 1, and cause the kernel to write up to 127 bytes beyond the region it proved it owns. On these Cortex-M33 targets there is no MMU, so user partitions and kernel data share one SRAM and the overflow can land in adjacent kernel state. The same defect is reached from kernel mode by any caller requesting a non-word-multiple length, including getentropy() and, in builds where sys_csrand_get()/sys_rand_get() resolve to the hardware generator, sys_rand8_get() and sys_rand16_get(). Impact is memory corruption of up to 127 bytes immediately following the supplied buffer β€” typically the caller's stack in kernel-mode use, or memory outside the caller's partition when driven through the syscall. The overflow offset is fully determined by the requested length and is therefore deterministic, while the written content is uncontrolled TRNG output; the practical consequences range from crashes and unpredictable state corruption to opportunistic escalation when kernel bookkeeping such as object permission bitmaps is overwritten. The affected devices are those where the MCUX SDK enables TRNG_SW_HEALTH_TESTS (MIMXRT595S, MIMXRT555S, MIMXRT533S, MIMXRT685S, MIMXRT633S), on which the TRNG is the zephyr,entropy chosen node; other SoCs using this driver take the SDK path that clamps the copy size and are unaffected. The fix routes any unaligned prefix and any sub-word tail through a local bounce word and hands the SDK only word-multiple sizes, so the SDK's word-granular writes can no longer pass the end of the caller's buffer.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-12
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zephyrproject zephyr 4.3.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-19736 is a buffer overflow in the NXP MCUX TRNG entropy driver for Zephyr RTOS. When TRNG_SW_HEALTH_TESTS is enabled, the SDK writes random data in 32-bit word chunks but rounds the requested length up to a multiple of 128 bytes. If the caller's buffer length is not a multiple of four bytes, the driver's length underflows, causing the SDK to write up to 127 extra bytes beyond the buffer. This corrupts adjacent memory, potentially affecting kernel state or user partitions.

Detection Guidance

This vulnerability affects specific NXP i.MX RT5xx and RT6xx devices running Zephyr RTOS with the MCUX TRNG entropy driver. Detection requires checking the device model and Zephyr configuration. Inspect the kernel configuration for TRNG_SW_HEALTH_TESTS and verify if the device is one of MIMXRT595S, MIMXRT555S, MIMXRT533S, MIMXRT685S, or MIMXRT633S. No direct network detection commands exist; focus on system inspection.

Impact Analysis

The vulnerability allows memory corruption of up to 127 bytes beyond the caller's buffer. In user mode with CONFIG_USERSPACE enabled, unprivileged threads can overwrite adjacent kernel memory. In kernel mode, functions like getentropy() or sys_rand*_get() can corrupt kernel state. This may cause crashes, unpredictable behavior, or privilege escalation if kernel bookkeeping data is overwritten.

Compliance Impact

This vulnerability could lead to memory corruption, crashes, or privilege escalation, which may compromise data confidentiality and integrity. For GDPR, this could result in unauthorized access to personal data. For HIPAA, it might expose protected health information. Both standards require safeguards against such breaches, and this flaw undermines those protections.

Mitigation Strategies
  • Apply the official patch from Zephyr RTOS by updating to the latest version or backported releases (v4.3, v4.4) that include the fix.
  • Disable CONFIG_USERSPACE if enabled to prevent unprivileged user-mode exploitation via syscalls.
  • Avoid using syscalls like entropy_get_entropy(), getentropy(), sys_rand8_get(), or sys_rand16_get() with non-word-multiple buffer lengths until patched.
  • Monitor kernel logs for crashes or memory corruption near entropy-related operations as potential signs of exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19736. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart