OP-TEE Trusted OS是OP-TEE组织的一款可信执行环境操作系统。 OP-TEE Trusted OS 4.10.0及之前版本存在安全漏洞,该漏洞源于Trusted Application loader存在释放后重用问题,攻击者可通过设置TA_FLAG_CONCURRENT标志使并发会话无锁操作同一共享上下文,导致memref参数映射和取消映射过程中释放仍在使用的vm_region节点,破坏安全世界内核内存。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71969 | 6.7 MEDIUM | OP-TEE OS 4.10.0 Buffer Underwrite via RSA NOPAD Encrypt/Decrypt Operations |
| CVE-2026-71967 | 5.5 MEDIUM | OP-TEE OS 4.10.0 NULL Pointer Dereference DoS via Widevine PTA open_session |
No comments yet