Vulnerabilities in OP-TEE

19 results
Vexday analysis

OP-TEE apresenta 16 vulnerabilidades catalogadas, com 13 delas publicadas nos últimos 90 dias, sinalizando um período de descobertas recentes intenso. Nenhuma vulnerabilidade está sob exploração ativa (KEV) e não há falhas classificadas como críticas, reduzindo o risco imediato. A fraqueza dominante é CWE-208 (Observable Timing Discrepancy), típica de problemas criptográficos, sugerindo focos em canais auxiliares mais que em execução arbitrária de código.

CVE-2022-46152HIGHOP-TEE Trusted OS vulnerable to Improper Validation of Array Index in the cleanup_shm_refs functionEPSS 0.5%CVE-2026-33662HIGHOP-TEE: RSASSA EMSA- PKCS1-v1_5 underflow in emsa_pkcs1_v1_5_encode()EPSS 0.4%CVE-2023-41325HIGHOP-TEE double free in shdr_verify_signatureEPSS 0.4%CVE-2026-53763LOWOP-TEE has AES-GCM 32-bit integer overflow in length counters that breaks authentication guaranteeEPSS 0.2%CVE-2026-40290HIGHOP-TEE has a Use-After-Free race in FF-A shared-memory teardownEPSS 0.2%CVE-2026-33317HIGHOP-TEE: PKCS#11 TA out-of-bounds read and memory disclosureEPSS 0.2%CVE-2026-44362MEDIUMOP-TEE's subkey rollback protection can be bypassed with older subkey versionsEPSS 0.2%CVE-2026-45702MEDIUMOP-TEE has FF-A type confusion in SPMC tmem path that causes S-EL1 kernel panicEPSS 0.2%CVE-2026-40257MEDIUMOP-TEE has SHA-3 accelerated finalize heap overflowEPSS 0.2%CVE-2026-41434LOWOP-TEE has unbounded recursion in sanitize_client_object()EPSS 0.2%CVE-2026-42546LOWOP-TEE has missing OPTEE_MSG_ATTR_TYPE_MASK in cleanup_shm_refs() leaks mobj referencesEPSS 0.2%CVE-2025-46733HIGHREE userspace code can panic TAs, leading to fTPM PCR reset and data disclosureEPSS 0.1%CVE-2026-41516LOWOP-TEE: Hisilicon HPRE PKCS#1 v1.5 Decryption Padding OracleEPSS 0.1%CVE-2026-41514LOWOP-TEE: RSA-OAEP padding oracle in Hisilicon HPRE driver enables plaintext recoveryEPSS 0.1%CVE-2026-71969HIGHOP-TEE OS 4.10.0 Buffer Underwrite via RSA NOPAD Encrypt/Decrypt OperationsEPSS 0.1%CVE-2026-41515LOWOP-TEE: RSA-OAEP padding oracle in NXP CAAM driver enables plaintext recoveryEPSS 0.1%CVE-2026-71967MEDIUMOP-TEE OS 4.10.0 NULL Pointer Dereference DoS via Widevine PTA open_sessionEPSS 0.1%CVE-2026-71968HIGHOP-TEE OS 4.10.0 Use-After-Free via Trusted Application Loader TA_FLAG_CONCURRENTEPSS 0.1%CVE-2026-45614MEDIUMOP-TEE vulnerable to ECDH private key recoveryEPSS 0.1%