PT-2026-55972 · Op Tee · Op-Tee

CVE-2026-41514

·

Published

2026-07-06

·

Updated

2026-07-07

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OP-TEE versions 4.5.0 through 4.10.x
Description The RSA-OAEP decryption implementation in the Hisilicon HPRE crypto driver uses a non-constant-time memcmp() function for label hash verification and contains multiple distinguishable error paths. This creates a Manger-style padding oracle, which is a side-channel attack that allows an attacker to recover RSA-OAEP plaintext by analyzing the differences in error responses. This issue specifically affects plat-d06 when the CFG HISILICON ACC V3 variable is set to y.
Recommendations Update to version 4.11.0. Disable the Hisilicon HPRE RSA driver by setting the CFG HISILICON ACC V3 variable to n.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41514

Affected Products

Op-Tee