OP-TEE optee_os是OP-TEE的安全操作系统。 OP-TEE optee_os 3.21.0版本至4.11.0之前版本存在缓冲区错误漏洞,该漏洞源于ARM Crypto Extensions加速SHA-3实现中存在差一错误,可能导致堆溢出,从而破坏哈希状态之后的所有TEE内核内存。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-44362 | 5.5 MEDIUM | OP-TEE's subkey rollback protection can be bypassed with older subkey versions |
| CVE-2026-42546 | 3.8 LOW | OP-TEE has missing OPTEE_MSG_ATTR_TYPE_MASK in cleanup_shm_refs() leaks mobj references |
| CVE-2026-41434 | 3.3 LOW | OP-TEE has unbounded recursion in sanitize_client_object() |
| CVE-2026-41514 | 2.5 LOW | OP-TEE: RSA-OAEP padding oracle in Hisilicon HPRE driver enables plaintext recovery |
| CVE-2026-41516 | 2.5 LOW | OP-TEE: Hisilicon HPRE PKCS#1 v1.5 Decryption Padding Oracle |
| CVE-2026-41515 | 2.5 LOW | OP-TEE: RSA-OAEP padding oracle in NXP CAAM driver enables plaintext recovery |
| CVE-2026-53763 | OP-TEE has AES-GCM 32-bit integer overflow in length counters that breaks authentication g |
No comments yet