Hi,
Thank you for your interest in NXP Semiconductor products,
Actually i.MX processors defconfigs have a lot of drivers and modules since it's the kernel that is going to be used in all Yocto images, including all their device tree and binary demos and the proof of concepts featuring them.
CVE risk is covered between every release, so this recommendation would be about the branch, use the latest one.
For size and boot time, you can start from imx_v8_defconfig and remove the drivers that your application won't need, it's mostly trial and error and application dependent.
Regards