PatchSiren cyber security CVE debrief
CVE-2026-19736 zephyrproject CVE debrief
An out-of-bounds write vulnerability exists in the NXP MCUX TRNG entropy driver within the Zephyr operating system. The vulnerability occurs when the driver is used with non-word-multiple request lengths on i.MX RT5xx and RT6xx parts. This allows an unprivileged user-mode thread to cause the kernel to write up to 127 bytes beyond the region it proved it owns, potentially leading to privilege escalation.
- Vendor
- zephyrproject
- Product
- zephyr
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-11
- Original CVE updated
- 2026-10-11
- Advisory published
- 2026-10-11
- Advisory updated
- 2026-10-11
Who should care
Defenders of systems using the Zephyr operating system with the NXP MCUX TRNG entropy driver should assess exposure and apply patches or mitigations as necessary. This includes developers and administrators responsible for maintaining and securing Zephyr-based systems, especially those using i.MX RT5xx and RT6xx parts.
Why it matters
The vulnerability allows an unprivileged user-mode thread to cause the kernel to write beyond the region it proved it owns, potentially leading to privilege escalation or data corruption. Defenders should assess exposure and apply patches or mitigations as necessary.
- Potential privilege escalation for unprivileged user-mode threads
- Possible data corruption or unauthorized access to sensitive information
- Increased risk of system compromise or denial-of-service attacks
Technical summary
The NXP MCUX TRNG entropy driver in drivers/entropy/entropy_mcux_trng.c passes the caller's byte count straight to the vendor SDK routine TRNG_GetRandomData(). On i.MX RT5xx and RT6xx parts, the SDK compiles its TRNG_SW_HEALTH_TESTS variant, which always copies whole 32-bit words and draws entropy rounded up to a multiple of 128 bytes. This can cause an out-of-bounds write when the request length is not a multiple of four.
Defensive priority
High
Recommended defensive actions
- Review and apply the patch provided by the vendor
- Restrict access to the entropy device to privileged users only
- Monitor for potential exploitation attempts
- Perform a thorough review of system configurations and user privileges
- Implement additional monitoring and logging to detect potential exploitation attempts
- Conduct a thorough asset inventory to identify potentially affected systems
- Track and document changes to the system until a patch is applied
Evidence notes
The vulnerability is caused by the NXP MCUX TRNG entropy driver passing the caller's byte count straight to the vendor SDK routine TRNG_GetRandomData(). The SDK always copies whole 32-bit words and draws entropy rounded up to a multiple of 128 bytes. The entropy_get_entropy() syscall and its verifier only validate the requested length via K_SYSCALL_MEMORY_WRITE().
Sources and references
Verified primary and authoritative sources
-
CVE-2026-19736 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-19736
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-19736 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19736
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Out-of-bounds write in the NXP MCUX TRNG entropy driver for non-word-multiple request lengths
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/19xxx/CVE-2026-19736.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/zephyrproject-rtos/zephyr/commit/2c132efaf03a5d45aeaf7b0531c1107db7a36a3d
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-3f6q-3949-rqph
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.