PT-2026-55954 · Trustedfirmware+3 · Op-Tee+1
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
OP-TEE versions 3.21.0 through 4.10.0
Description
An off-by-one error exists in the ARM Crypto Extensions accelerated SHA-3 implementation. This flaw can lead to a massive heap overflow, resulting in the corruption of TEE kernel memory following the hash state. The issue specifically impacts platforms configured with
CFG CRYPTO WITH CE82=y, which enables SHA3 Crypto Extensions on ARMv8.2+ architectures.Recommendations
Update to version 4.11.0.
Disable SHA3 Crypto Extensions by setting
CFG CRYPTO WITH CE82=n.Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Op-Tee
Optee Os