Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-71968— OP-TEE OS 4.10.0 Use-After-Free via Trusted Application Loader TA_FLAG_CONCURRENT

Quick assessment

Affected
OP-TEE optee_os
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

OP-TEE Trusted OS是OP-TEE组织的一款可信执行环境操作系统。 OP-TEE Trusted OS 4.10.0及之前版本存在安全漏洞,该漏洞源于Trusted Application loader存在释放后重用问题,攻击者可通过设置TA_FLAG_CONCURRENT标志使并发会话无锁操作同一共享上下文,导致memref参数映射和取消映射过程中释放仍在使用的vm_region节点,破坏安全世界内核内存。

CVSS 6.7 · Medium EPSS 0.14% · P3

Possible ATT&CK Techniques 1 AI

T1612 · Build Image on Host

Affected Version Matrix 2

VendorProduct Version RangeStatus
OP-TEE optee_os ≤ 4.10.0 affected
8794043c4065c26a2b8b1313794ba5ba5f06d296 unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-71968

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
OP-TEE OS 4.10.0 Use-After-Free via Trusted Application Loader TA_FLAG_CONCURRENT
Source: CVE Program / CVE List V5
Vulnerability Description
OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a use-after-free vulnerability in the Trusted Application loader that allows attackers with the ability to load a signed Trusted Application to corrupt secure-world kernel memory by setting the TA_FLAG_CONCURRENT flag in a user TA signed header. Attackers can cause two concurrent sessions to operate on the same shared context without locking, corrupting the uctx->vm_info.regions list during memref parameter mapping and unmapping to free vm_region nodes still in use, resulting in a use-after-free in S-EL1 secure-world kernel memory.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
释放后使用
Source: CVE Program / CVE List V5
Vulnerability Title
OP-TEE Trusted OS 竞争条件问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
OP-TEE Trusted OS是OP-TEE组织的一款可信执行环境操作系统。 OP-TEE Trusted OS 4.10.0及之前版本存在安全漏洞,该漏洞源于Trusted Application loader存在释放后重用问题,攻击者可通过设置TA_FLAG_CONCURRENT标志使并发会话无锁操作同一共享上下文,导致memref参数映射和取消映射过程中释放仍在使用的vm_region节点,破坏安全世界内核内存。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
OP-TEE optee_os 0 ~ 4.10.0 -

II. Public POCs for CVE-2026-71968

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-71968

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-71968 (2)

Vendor Advisories for CVE-2026-71968 (1)

Same Patch Batch · OP-TEE · 2026-08-10 · 3 CVEs total

CVE-2026-71969 6.7 MEDIUM OP-TEE OS 4.10.0 Buffer Underwrite via RSA NOPAD Encrypt/Decrypt Operations
CVE-2026-71967 5.5 MEDIUM OP-TEE OS 4.10.0 NULL Pointer Dereference DoS via Widevine PTA open_session

IV. Related Vulnerabilities

V. Comments for CVE-2026-71968

No comments yet


Leave a comment