Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · nxp

nxp

· 1 Critical

Total CVEs

20

Critical

1

Products

213

Search All CVEs →

20

Products (213)

mcuxpresso software development kit5 CVEsi.mx 6ull4 CVEsi.mx 6ultralite4 CVEsi.mx 6solox4 CVEslpc55s69jbd1003 CVEslpc55s69jbd100 firmware3 CVEslpc55s69jbd643 CVEslpc55s69jbd64 firmware3 CVEslpc55s69jev983 CVEslpc55s69jev98 firmware3 CVEsi.mx 6dual3 CVEsi.mx 6dual firmware3 CVEsi.mx 6duallite3 CVEsi.mx 6duallite firmware3 CVEsi.mx 6dualplus3 CVEsi.mx 6dualplus firmware3 CVEsi.mx 6quad3 CVEsi.mx 6quad firmware3 CVEsi.mx 6quadplus3 CVEsi.mx 6quadplus firmware3 CVEsi.mx 6solo3 CVEsi.mx 6ull firmware3 CVEsi.mx 6ultralite firmware3 CVEsi.mx 6solo firmware3 CVEsi.mx 6sololite3 CVEsi.mx 6sololite firmware3 CVEsi.mx 6solox firmware3 CVEsi.mx 8m mini2 CVEsvybrid mvf30nn151cku262 CVEsvybrid mvf30nn151cku26 firmware2 CVEsvybrid mvf30ns151cku262 CVEsvybrid mvf30ns151cku26 firmware2 CVEsvybrid mvf50nn151cmk402 CVEsvybrid mvf50nn151cmk40 firmware2 CVEsvybrid mvf50nn151cmk502 CVEsvybrid mvf50nn151cmk50 firmware2 CVEsvybrid mvf50ns151cmk402 CVEsvybrid mvf50ns151cmk40 firmware2 CVEsvybrid mvf50ns151cmk502 CVEsvybrid mvf50ns151cmk50 firmware2 CVEsvybrid mvf51nn151cmk502 CVEsvybrid mvf51nn151cmk50 firmware2 CVEsvybrid mvf51ns151cmk502 CVEsvybrid mvf51ns151cmk50 firmware2 CVEsvybrid mvf60nn151cmk402 CVEsvybrid mvf60nn151cmk40 firmware2 CVEsvybrid mvf60nn151cmk502 CVEsvybrid mvf60nn151cmk50 firmware2 CVEsvybrid mvf60ns151cmk402 CVEsvybrid mvf60ns151cmk40 firmware2 CVEsvybrid mvf60ns151cmk502 CVEsvybrid mvf60ns151cmk50 firmware2 CVEsvybrid mvf61nn151cmk502 CVEsvybrid mvf61nn151cmk50 firmware2 CVEsvybrid mvf61ns151cmk502 CVEsvybrid mvf61ns151cmk50 firmware2 CVEsvybrid mvf62nn151cmk402 CVEsvybrid mvf62nn151cmk40 firmware2 CVEsi.mx 6ulz2 CVEsi.mx 50 firmware2 CVEsi.mx 532 CVEsi.mx 7dual2 CVEsi.mx 7dual firmware2 CVEskinetis k8x2 CVEslpc55s66jbd1002 CVEslpc55s66jbd100 firmware2 CVEskinetis k8x firmware2 CVEskinetis kv1x2 CVEskinetis kv1x firmware2 CVEskinetis kv3x2 CVEskinetis kv3x firmware2 CVEskw31z2 CVEskw342 CVEskw352 CVEskw362 CVEskw372 CVEskw382 CVEskw392 CVEskw41z2 CVEsi.mx 7solo2 CVEsi.mx 7solo firmware2 CVEsi.mx 53 firmware2 CVEsi.mx 62 CVEsi.mx 502 CVEslpc5528 firmware1 CVEslpc55s14jbd1001 CVEslpc55s14jbd100 firmware1 CVEs3a0811 CVEslpc55s14jbd64 firmware1 CVEslpc55s16jbd1001 CVEslpc55s16jbd100 firmware1 CVEslpc55s16jbd641 CVEslpc55s16jbd64 firmware1 CVEslpc55s16jev981 CVEslpc55s16jev98 firmware1 CVEslpc55s261 CVEslpc55s26 firmware1 CVEslpc55s281 CVEslpc55s28 firmware1 CVEslpc55s66jbd641 CVEslpc55s66jbd64 firmware1 CVEslpc55s66jev981 CVEslpc55s66jev98 firmware1 CVEslpcs66jbd641 CVEslpcs66jbd64 firmware1 CVEslpcs66jev981 CVEslpcs66jev98 firmware1 CVEsmifare ultralight c1 CVEsmifare ultralight c firmware1 CVEsmifare ultralight ev11 CVEsmifare ultralight ev1 firmware1 CVEsmifare ultralight nano1 CVEsmifare ultralight nano firmware1 CVEsmqx1 CVEsntag 2101 CVEsntag 210 firmware1 CVEsntag 2121 CVEsntag 212 firmware1 CVEsntag 2131 CVEsntag 213 firmware1 CVEsntag 2151 CVEsntag 215 firmware1 CVEsntag 2161 CVEsntag 216 firmware1 CVEsp50101 CVEsp50201 CVEsp50211 CVEsp50401 CVEsuboot secondary program loader1 CVEslpc55s14jbd641 CVEsa7005a1 CVEsi.mx6sx1 CVEsi.mx 281 CVEsi.mx 28 firmware1 CVEsi.mx 6 firmware1 CVEsi.mx 6ulz firmware1 CVEsi.mx 7ds1 CVEsi.mx 7ulp1 CVEsi.mx 7ulp firmware1 CVEsi.mx 8m1 CVEsi.mx 8m mini firmware1 CVEsi.mx 8m nano1 CVEsi.mx 8m plus1 CVEsi.mx 8m quad1 CVEsi.mx 8m quad firmware1 CVEsi.mx 8m vybrid1 CVEsi.mx 8m vybrid firmware1 CVEsi.mx rt10101 CVEsi.mx rt1010 firmware1 CVEsi.mx rt10151 CVEsi.mx rt1015 firmware1 CVEsi.mx rt10201 CVEsi.mx rt1020 firmware1 CVEsi.mx rt10501 CVEsi.mx rt1050 firmware1 CVEsi.mx rt10601 CVEsi.mx rt1060 firmware1 CVEsi.mx rt5001 CVEsi.mx rt500 firmware1 CVEsi.mx rt6001 CVEsi.mx rt600 firmware1 CVEsj2a0811 CVEsj2d081 m591 CVEsj2d081 m611 CVEsj2d082 m601 CVEsj2d120 m601 CVEsj2d145 m591 CVEsj2e081 m641 CVEsj2e082 m651 CVEsj2e120 m651 CVEsj2e145 m641 CVEsj3a0411 CVEsj3d081 m591 CVEsj3d081 m59 df1 CVEsj3d081 m611 CVEsj3d081 m61 df1 CVEsj3d082 m601 CVEsj3d120 m601 CVEsj3d145 m591 CVEsj3e016 m641 CVEsj3e016 m64 df1 CVEsj3e016 m661 CVEsj3e016 m66 df1 CVEsj3e041 m641 CVEsj3e041 m64 df1 CVEsj3e041 m661 CVEsj3e041 m66 df1 CVEsj3e081 m641 CVEsj3e081 m64 df1 CVEsj3e081 m661 CVEsj3e081 m66 df1 CVEsj3e082 m651 CVEsj3e120 m651 CVEsj3e145 m641 CVEskinetis k821 CVEskinetis k82 firmware1 CVEslpc5512jbd1001 CVEslpc5512jbd100 firmware1 CVEslpc5512jbd641 CVEslpc5512jbd64 firmware1 CVEslpc5514jbd1001 CVEslpc5514jbd100 firmware1 CVEslpc5514jbd641 CVEslpc5514jbd64 firmware1 CVEslpc5516jbd1001 CVEslpc5516jbd100 firmware1 CVEslpc5516jbd641 CVEslpc5516jbd64 firmware1 CVEslpc5516jev981 CVEslpc5516jev98 firmware1 CVEslpc55261 CVEslpc5526 firmware1 CVEslpc55281 CVEs

Recent Vulnerabilities

View all 20
CVE-2023-39902HIGH 7.0

A software vulnerability has been identified in the U-Boot Secondary Program Loader (SPL) before 2023.07 on select NXP i.MX 8M family processors. Under certain conditions, a crafted Flattened Image Tree (FIT) format structure can be used to overwrite SPL memory, allowing unauthenticated software to execute on the target, leading to privilege escalation. This affects i.MX 8M, i.MX 8M Mini, i.MX 8M Nano, and i.MX 8M Plus.

CVE-2022-45163MEDIUM 5.3

An information-disclosure vulnerability exists on select NXP devices when configured in Serial Download Protocol (SDP) mode: i.MX RT 1010, i.MX RT 1015, i.MX RT 1020, i.MX RT 1050, i.MX RT 1060, i.MX 6 Family, i.MX 7Dual/Solo, i.MX 7ULP, i.MX 8M Quad, i.MX 8M Mini, and Vybrid. In a device security-enabled configuration, memory contents could potentially leak to physically proximate attackers via the respective SDP port in cold and warm boot attacks. (The recommended mitigation is to completely disable the SDP mode by programming a one-time programmable eFUSE. Customers can contact NXP for additional information.)

CVE-2021-27421HIGH 7.3

NXP MCUXpresso SDK versions prior to 2.8.2 are vulnerable to integer overflow in SDK_Malloc function, which could allow to access memory locations outside the bounds of a specified array, leading to unexpected behavior such segmentation fault when assigning a particular block of memory from the heap via malloc.

CVE-2021-22680HIGH 7.3

NXP MQX Versions 5.1 and prior are vulnerable to integer overflow in mem_alloc, _lwmem_alloc and _partition functions. This unverified memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.

CVE-2022-22819HIGH 7.8

NXP LPC55S66JBD64, LPC55S66JBD100, LPC55S66JEV98, LPC55S69JBD64, LPC55S69JBD100, and LPC55S69JEV98 microcontrollers (ROM version 1B) have a buffer overflow in parsing SB2 updates before the signature is verified. This can allow an attacker to achieve non-persistent code execution via a crafted unsigned update.

CVE-2021-44149HIGH 7.8

An issue was discovered in Trusted Firmware OP-TEE Trusted OS through 3.15.0. The OPTEE-OS CSU driver for NXP i.MX6UL SoC devices lacks security access configuration for wakeup-related registers, resulting in TrustZone bypass because the NonSecure World can perform arbitrary memory read/write operations on Secure World memory. This involves a v cycle.

CVE-2021-36133HIGH 7.1

The OPTEE-OS CSU driver for NXP i.MX SoC devices lacks security access configuration for several models, resulting in TrustZone bypass because the NonSecure World can perform arbitrary memory read/write operations on Secure World memory. This involves a DMA capable peripheral.

CVE-2021-44479MEDIUM 6.1

NXP Kinetis K82 devices have a buffer over-read via a crafted wlength value in a GET Status-Other request during use of USB In-System Programming (ISP) mode. This discloses protected flash memory.

CVE-2021-40154MEDIUM 6.1

NXP LPC55S69 devices before A3 have a buffer over-read via a crafted wlength value in a GET Descriptor Configuration request during use of USB In-System Programming (ISP) mode. This discloses protected flash memory.

CVE-2021-38260HIGH 7.8

NXP MCUXpresso SDK v2.7.0 was discovered to contain a buffer overflow in the function USB_HostParseDeviceConfigurationDescriptor().

CVE-2021-38258HIGH 7.8

NXP MCUXpresso SDK v2.7.0 was discovered to contain a buffer overflow in the function USB_HostProcessCallback().

CVE-2021-33881MEDIUM 4.2

On NXP MIFARE Ultralight and NTAG cards, an attacker can interrupt a write operation (aka conduct a "tear off" attack) over RFID to bypass a Monotonic Counter protection mechanism. The impact depends on how the anti tear-off feature is used in specific applications such as public transportation, physical access control, etc.

CVE-2021-31532MEDIUM 6.8

NXP LPC55S6x microcontrollers (0A and 1B), i.MX RT500 (silicon rev B1 and B2), i.MX RT600 (silicon rev A0, B0), LPC55S6x, LPC55S2x, LPC552x (silicon rev 0A, 1B), LPC55S1x, LPC551x (silicon rev 0A) and LPC55S0x, LPC550x (silicon rev 0A) include an undocumented ROM patch peripheral that allows unsigned, non-persistent modification of the internal ROM.

CVE-2021-3011MEDIUM 4.2

An electromagnetic-wave side-channel issue was discovered on NXP SmartMX / P5x security microcontrollers and A7x secure authentication microcontrollers, with CryptoLib through v2.9. It allows attackers to extract the ECDSA private key after extensive physical access (and consequently produce a clone). This was demonstrated on the Google Titan Security Key, based on an NXP A7005a chip. Other FIDO U2F security keys are also impacted (Yubico YubiKey Neo and Feitian K9, K13, K21, and K40) as well as several NXP JavaCard smartcards (J3A081, J2A081, J3A041, J3D145_M59, J2D145_M59, J3D120_M60, J3D082_M60, J2D120_M60, J2D082_M60, J3D081_M59, J2D081_M59, J3D081_M61, J2D081_M61, J3D081_M59_DF, J3D081_M61_DF, J3E081_M64, J3E081_M66, J2E081_M64, J3E041_M66, J3E016_M66, J3E016_M64, J3E041_M64, J3E145_M64, J3E120_M65, J3E082_M65, J2E145_M64, J2E120_M65, J2E082_M65, J3E081_M64_DF, J3E081_M66_DF, J3E041_M66_DF, J3E016_M66_DF, J3E041_M64_DF, and J3E016_M64_DF).

CVE-2019-17519HIGH 8.8

The Bluetooth Low Energy implementation on NXP SDK through 2.2.1 for KW41Z devices does not properly restrict the Link Layer payload length, allowing attackers in radio range to cause a buffer overflow via a crafted packet.

CVE-2019-17060MEDIUM 6.5

The Bluetooth Low Energy (BLE) stack implementation on the NXP KW41Z (based on the MCUXpresso SDK with Bluetooth Low Energy Driver 2.2.1 and earlier) does not properly restrict the BLE Link Layer header and executes certain memory contents upon receiving a packet with a Link Layer ID (LLID) equal to zero. This allows attackers within radio range to cause deadlocks, cause anomalous behavior in the BLE state machine, or trigger a buffer overflow via a crafted BLE Link Layer frame.

CVE-2019-14239MEDIUM 6.6

On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only access) can be defeated by leveraging a load instruction inside the execute-only region to expose the protected code into a CPU register.

CVE-2019-14237CRITICAL 9.8

On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only access) can be defeated by observing CPU registers and the effect of code/instruction execution.

CVE-2017-7936

A stack-based buffer overflow issue was discovered in NXP i.MX 50, i.MX 53, i.MX 6ULL, i.MX 6UltraLite, i.MX 6SoloLite, i.MX 6Solo, i.MX 6DualLite, i.MX 6SoloX, i.MX 6Dual, i.MX 6Quad, i.MX 6DualPlus, i.MX 6QuadPlus, Vybrid VF3xx, Vybrid VF5xx, and Vybrid VF6xx. When the device is configured in security enabled configuration, SDP could be used to download a small section of code to an unprotected region of memory.

CVE-2017-7932

An improper certificate validation issue was discovered in NXP i.MX 28 i.MX 50, i.MX 53, i.MX 7Solo i.MX 7Dual Vybrid VF3xx, Vybrid VF5xx, Vybrid VF6xx, i.MX 6ULL, i.MX 6UltraLite, i.MX 6SoloLite, i.MX 6Solo, i.MX 6DualLite, i.MX 6SoloX, i.MX 6Dual, i.MX 6Quad, i.MX 6DualPlus, and i.MX 6QuadPlus. When the device is configured in security enabled configuration, under certain conditions it is possible to bypass the signature verification by using a specially crafted certificate leading to the execution of an unsigned image.