Impact
The NXP MCUX TRNG entropy driver in Zephyr forwards the caller’s requested count directly to the vendor SDK routine TRNG_GetRandomData(). On i.MX RT5xx and RT6xx parts that enable the TRNG_SW_HEALTH_TESTS variant, the SDK copies data in 32‑bit word chunks and rounds the length up to a multiple of 128 bytes. Because the driver does not align or truncate the length, a request whose length is not a multiple of four causes an out‑of‑bounds write (CWE‑787). This results in up to 127 bytes of random data being written beyond the end of the caller’s buffer, potentially corrupting adjacent memory such as the kernel stack or object permission bitmaps.
Affected Systems
Affected systems are Zephyr builds that use the MCUX SDK on i.MX RT5xx and RT6xx parts where TRNG_SW_HEALTH_TESTS is enabled, such as MIMXRT595S, MIMXRT555S, MIMXRT533S, MIMXRT685S, and MIMXRT633S. Other SoCs that use a different driver path are not impacted.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. Exploitation is possible from user space when a process has been granted access to the entropy device; there is no MMU on the Cortex‑M33 targets, so the overflow can overwrite adjacent kernel memory. Kernel callers such as sys_rand_* and getentropy() also trigger the flaw by requesting non‑word‑multiple lengths. The attack involves requesting a 1‑byte or any non‑multiple‑of‑four length, causing the driver to write 128 bytes of random data beyond the caller’s buffer. Because the overflow offset is deterministic, detection is difficult and the practical risk is high in vulnerable configurations, with possible crashes, state corruption, or privilege escalation.
OpenCVE Enrichment