PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-19736 zephyrproject CVE debrief

An out-of-bounds write vulnerability exists in the NXP MCUX TRNG entropy driver within the Zephyr operating system. The vulnerability occurs when the driver is used with non-word-multiple request lengths on i.MX RT5xx and RT6xx parts. This allows an unprivileged user-mode thread to cause the kernel to write up to 127 bytes beyond the region it proved it owns, potentially leading to privilege escalation.

Vendor
zephyrproject
Product
zephyr
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-11
Original CVE updated
2026-10-11
Advisory published
2026-10-11
Advisory updated
2026-10-11

Who should care

Defenders of systems using the Zephyr operating system with the NXP MCUX TRNG entropy driver should assess exposure and apply patches or mitigations as necessary. This includes developers and administrators responsible for maintaining and securing Zephyr-based systems, especially those using i.MX RT5xx and RT6xx parts.

Why it matters

The vulnerability allows an unprivileged user-mode thread to cause the kernel to write beyond the region it proved it owns, potentially leading to privilege escalation or data corruption. Defenders should assess exposure and apply patches or mitigations as necessary.

  • Potential privilege escalation for unprivileged user-mode threads
  • Possible data corruption or unauthorized access to sensitive information
  • Increased risk of system compromise or denial-of-service attacks

Technical summary

The NXP MCUX TRNG entropy driver in drivers/entropy/entropy_mcux_trng.c passes the caller's byte count straight to the vendor SDK routine TRNG_GetRandomData(). On i.MX RT5xx and RT6xx parts, the SDK compiles its TRNG_SW_HEALTH_TESTS variant, which always copies whole 32-bit words and draws entropy rounded up to a multiple of 128 bytes. This can cause an out-of-bounds write when the request length is not a multiple of four.

Defensive priority

High

Recommended defensive actions

  • Review and apply the patch provided by the vendor
  • Restrict access to the entropy device to privileged users only
  • Monitor for potential exploitation attempts
  • Perform a thorough review of system configurations and user privileges
  • Implement additional monitoring and logging to detect potential exploitation attempts
  • Conduct a thorough asset inventory to identify potentially affected systems
  • Track and document changes to the system until a patch is applied

Evidence notes

The vulnerability is caused by the NXP MCUX TRNG entropy driver passing the caller's byte count straight to the vendor SDK routine TRNG_GetRandomData(). The SDK always copies whole 32-bit words and draws entropy rounded up to a multiple of 128 bytes. The entropy_get_entropy() syscall and its verifier only validate the requested length via K_SYSCALL_MEMORY_WRITE().

Sources and references

Verified primary and authoritative sources

  • CVE-2026-19736 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-19736

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-19736 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19736

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.