PatchSiren

NXP CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM NXP CVE published 2026-10-08

CVE-2017-20283

This PatchSiren debrief is based on the supplied CVE record and source item. The CVE record was published on 2026-10-08T02:12:10.697Z and has not been modified since then. The NXP MQX Classic before 5.0 contains an out-of-bounds write vulnerability in the RTCS UDP recvfrom() implementation. Improper enforcement of the application-supplied receive buffer length may allow a crafted UDP packet to overflow th [truncated]

LOW NXP CVE published 2026-10-08

CVE-2026-87726

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-10-08T02:04:18.602Z and has not been modified since then. CVE-2026-87726 involves insufficient API bounds checking in phalFelica within NXP's NXPNfcRdLib RC663 through version 07.14.00_Pub. This issue may allow an attacker with privileges or an untrusted third party to access unintended memory regions, [truncated]