OP-TEE optee_os是OP-TEE的安全操作系统。 OP-TEE optee_os 4.5.0版本至4.11.0之前版本存在日志信息泄露漏洞,该漏洞源于Hisilicon HPRE加密驱动程序中RSA PKCS#1 v1.5解密实现使用了非恒定时间的memcmp()进行标签哈希验证,并具有多个可区分的错误路径,可能导致攻击者恢复RSA PKCS#1 v1.5明文。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-40257 | 5.5 MEDIUM | OP-TEE has SHA-3 accelerated finalize heap overflow |
| CVE-2026-44362 | 5.5 MEDIUM | OP-TEE's subkey rollback protection can be bypassed with older subkey versions |
| CVE-2026-42546 | 3.8 LOW | OP-TEE has missing OPTEE_MSG_ATTR_TYPE_MASK in cleanup_shm_refs() leaks mobj references |
| CVE-2026-41434 | 3.3 LOW | OP-TEE has unbounded recursion in sanitize_client_object() |
| CVE-2026-41514 | 2.5 LOW | OP-TEE: RSA-OAEP padding oracle in Hisilicon HPRE driver enables plaintext recovery |
| CVE-2026-41515 | 2.5 LOW | OP-TEE: RSA-OAEP padding oracle in NXP CAAM driver enables plaintext recovery |
| CVE-2026-53763 | OP-TEE has AES-GCM 32-bit integer overflow in length counters that breaks authentication g |
No comments yet