OP-TEE optee_os是OP-TEE的安全操作系统。 OP-TEE optee_os 4.5.0版本至4.11.0之前版本存在日志信息泄露漏洞,该漏洞源于Hisilicon HPRE加密驱动程序中RSA-OAEP解密实现使用非常量时间memcmp进行标签哈希验证,并且存在多个可区分的错误路径,形成香草填充预言机攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-40257 | 5.5 MEDIUM | OP-TEE has SHA-3 accelerated finalize heap overflow |
| CVE-2026-44362 | 5.5 MEDIUM | OP-TEE's subkey rollback protection can be bypassed with older subkey versions |
| CVE-2026-42546 | 3.8 LOW | OP-TEE has missing OPTEE_MSG_ATTR_TYPE_MASK in cleanup_shm_refs() leaks mobj references |
| CVE-2026-41434 | 3.3 LOW | OP-TEE has unbounded recursion in sanitize_client_object() |
| CVE-2026-41516 | 2.5 LOW | OP-TEE: Hisilicon HPRE PKCS#1 v1.5 Decryption Padding Oracle |
| CVE-2026-41515 | 2.5 LOW | OP-TEE: RSA-OAEP padding oracle in NXP CAAM driver enables plaintext recovery |
| CVE-2026-53763 | OP-TEE has AES-GCM 32-bit integer overflow in length counters that breaks authentication g |
No comments yet