Description
The NXP MCUX TRNG entropy driver in drivers/entropy/entropy_mcux_trng.c passed the caller's byte count straight to the vendor SDK routine TRNG_GetRandomData(). On i.MX RT5xx and RT6xx parts the SDK compiles its TRNG_SW_HEALTH_TESTS variant, which always copies whole 32-bit words and draws entropy rounded up to a multiple of 128 bytes. Its "caller buffer is full" guard tests dataSize == 0, so a request whose length is not a multiple of four makes dataSize underflow past zero and the SDK keeps writing into the caller's buffer for the entire extraction: a 1-byte request results in 128 bytes written, and any non-word-multiple length overflows by up to 127 bytes.

entropy_get_entropy() is a syscall, and its verifier in drivers/entropy/entropy_handlers.c validates only the requested length via K_SYSCALL_MEMORY_WRITE(). With CONFIG_USERSPACE enabled, an unprivileged user-mode thread that has merely been granted the entropy device can therefore choose both the destination address and a length such as 1, and cause the kernel to write up to 127 bytes beyond the region it proved it owns. On these Cortex-M33 targets there is no MMU, so user partitions and kernel data share one SRAM and the overflow can land in adjacent kernel state. The same defect is reached from kernel mode by any caller requesting a non-word-multiple length, including getentropy() and, in builds where sys_csrand_get()/sys_rand_get() resolve to the hardware generator, sys_rand8_get() and sys_rand16_get().

Impact is memory corruption of up to 127 bytes immediately following the supplied buffer — typically the caller's stack in kernel-mode use, or memory outside the caller's partition when driven through the syscall. The overflow offset is fully determined by the requested length and is therefore deterministic, while the written content is uncontrolled TRNG output; the practical consequences range from crashes and unpredictable state corruption to opportunistic escalation when kernel bookkeeping such as object permission bitmaps is overwritten. The affected devices are those where the MCUX SDK enables TRNG_SW_HEALTH_TESTS (MIMXRT595S, MIMXRT555S, MIMXRT533S, MIMXRT685S, MIMXRT633S), on which the TRNG is the zephyr,entropy chosen node; other SoCs using this driver take the SDK path that clamps the copy size and are unaffected.

The fix routes any unaligned prefix and any sub-word tail through a local bounce word and hands the SDK only word-multiple sizes, so the SDK's word-granular writes can no longer pass the end of the caller's buffer.
Published: 2026-10-11
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Kernel Memory Corruption
Action: Immediate Patch
AI Analysis

Impact

The NXP MCUX TRNG entropy driver in Zephyr forwards the caller’s requested count directly to the vendor SDK routine TRNG_GetRandomData(). On i.MX RT5xx and RT6xx parts that enable the TRNG_SW_HEALTH_TESTS variant, the SDK copies data in 32‑bit word chunks and rounds the length up to a multiple of 128 bytes. Because the driver does not align or truncate the length, a request whose length is not a multiple of four causes an out‑of‑bounds write (CWE‑787). This results in up to 127 bytes of random data being written beyond the end of the caller’s buffer, potentially corrupting adjacent memory such as the kernel stack or object permission bitmaps.

Affected Systems

Affected systems are Zephyr builds that use the MCUX SDK on i.MX RT5xx and RT6xx parts where TRNG_SW_HEALTH_TESTS is enabled, such as MIMXRT595S, MIMXRT555S, MIMXRT533S, MIMXRT685S, and MIMXRT633S. Other SoCs that use a different driver path are not impacted.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity. Exploitation is possible from user space when a process has been granted access to the entropy device; there is no MMU on the Cortex‑M33 targets, so the overflow can overwrite adjacent kernel memory. Kernel callers such as sys_rand_* and getentropy() also trigger the flaw by requesting non‑word‑multiple lengths. The attack involves requesting a 1‑byte or any non‑multiple‑of‑four length, causing the driver to write 128 bytes of random data beyond the caller’s buffer. Because the overflow offset is deterministic, detection is difficult and the practical risk is high in vulnerable configurations, with possible crashes, state corruption, or privilege escalation.

Generated by OpenCVE AI on October 11, 2026 at 18:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Zephyr to a revision that includes the driver patch (commit 2c132efaf03a5d45aeaf7b0531c1107db7a36a3d).
  • Rebuild or upgrade the NXP MCUX SDK so that TRNG_GetRandomData() receives only word‑aligned lengths, preventing the SDK from writing beyond the supplied buffer.
  • If patching is not immediately possible, restrict or remove unprivileged access to the entropy device or disable CONFIG_USERSPACE so user‑mode exploitation is blocked.

Generated by OpenCVE AI on October 11, 2026 at 18:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Zephyrproject
Zephyrproject zephyr
Vendors & Products Zephyrproject
Zephyrproject zephyr

Sun, 11 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Description The NXP MCUX TRNG entropy driver in drivers/entropy/entropy_mcux_trng.c passed the caller's byte count straight to the vendor SDK routine TRNG_GetRandomData(). On i.MX RT5xx and RT6xx parts the SDK compiles its TRNG_SW_HEALTH_TESTS variant, which always copies whole 32-bit words and draws entropy rounded up to a multiple of 128 bytes. Its "caller buffer is full" guard tests dataSize == 0, so a request whose length is not a multiple of four makes dataSize underflow past zero and the SDK keeps writing into the caller's buffer for the entire extraction: a 1-byte request results in 128 bytes written, and any non-word-multiple length overflows by up to 127 bytes. entropy_get_entropy() is a syscall, and its verifier in drivers/entropy/entropy_handlers.c validates only the requested length via K_SYSCALL_MEMORY_WRITE(). With CONFIG_USERSPACE enabled, an unprivileged user-mode thread that has merely been granted the entropy device can therefore choose both the destination address and a length such as 1, and cause the kernel to write up to 127 bytes beyond the region it proved it owns. On these Cortex-M33 targets there is no MMU, so user partitions and kernel data share one SRAM and the overflow can land in adjacent kernel state. The same defect is reached from kernel mode by any caller requesting a non-word-multiple length, including getentropy() and, in builds where sys_csrand_get()/sys_rand_get() resolve to the hardware generator, sys_rand8_get() and sys_rand16_get(). Impact is memory corruption of up to 127 bytes immediately following the supplied buffer — typically the caller's stack in kernel-mode use, or memory outside the caller's partition when driven through the syscall. The overflow offset is fully determined by the requested length and is therefore deterministic, while the written content is uncontrolled TRNG output; the practical consequences range from crashes and unpredictable state corruption to opportunistic escalation when kernel bookkeeping such as object permission bitmaps is overwritten. The affected devices are those where the MCUX SDK enables TRNG_SW_HEALTH_TESTS (MIMXRT595S, MIMXRT555S, MIMXRT533S, MIMXRT685S, MIMXRT633S), on which the TRNG is the zephyr,entropy chosen node; other SoCs using this driver take the SDK path that clamps the copy size and are unaffected. The fix routes any unaligned prefix and any sub-word tail through a local bounce word and hands the SDK only word-multiple sizes, so the SDK's word-granular writes can no longer pass the end of the caller's buffer.
Title Out-of-bounds write in the NXP MCUX TRNG entropy driver for non-word-multiple request lengths
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Zephyrproject Zephyr
cve-icon MITRE

Status: PUBLISHED

Assigner: zephyr

Published:

Updated: 2026-10-11T17:14:58.574Z

Reserved: 2026-08-13T13:46:26.118Z

Link: CVE-2026-19736

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T18:16:58.810

Modified: 2026-10-11T18:16:58.810

Link: CVE-2026-19736

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T19:00:14Z

Weaknesses