OP-TEE optee_os是OP-TEE的安全操作系统。 OP-TEE optee_os 3.3.0版本至4.11.0之前版本存在资源管理错误漏洞,该漏洞源于共享内存清理逻辑中存在资源泄漏,因为函数cleanup_shm_refs()未能对参数属性应用所需的位掩码,导致mobj_reg_shm对象持久引用泄漏,逐渐消耗安全世界堆空间,最终需要重启恢复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-40257 | 5.5 MEDIUM | OP-TEE has SHA-3 accelerated finalize heap overflow |
| CVE-2026-44362 | 5.5 MEDIUM | OP-TEE's subkey rollback protection can be bypassed with older subkey versions |
| CVE-2026-41434 | 3.3 LOW | OP-TEE has unbounded recursion in sanitize_client_object() |
| CVE-2026-41514 | 2.5 LOW | OP-TEE: RSA-OAEP padding oracle in Hisilicon HPRE driver enables plaintext recovery |
| CVE-2026-41516 | 2.5 LOW | OP-TEE: Hisilicon HPRE PKCS#1 v1.5 Decryption Padding Oracle |
| CVE-2026-41515 | 2.5 LOW | OP-TEE: RSA-OAEP padding oracle in NXP CAAM driver enables plaintext recovery |
| CVE-2026-53763 | OP-TEE has AES-GCM 32-bit integer overflow in length counters that breaks authentication g |
No comments yet