PT-2026-55973 · Nxp+1 · Caam+1

·

CVE-2026-41515

·

Published

2026-07-06

·

Updated

2026-07-07

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OP-TEE versions 3.9.0 through 4.10.x
Description The RSA-OAEP decryption implementation in the NXP CAAM crypto driver uses a non-constant-time memcmp() function for label hash verification and contains multiple distinguishable error paths. This creates a Manger-style padding oracle, which is a side-channel attack that allows an attacker to recover RSA-OAEP plaintext by sending approximately 1000-2000 adaptive chosen ciphertext queries.
Recommendations Update to version 4.11.0. Disable the NXP CAAM RSA driver by setting CFG CRYPTO DRV RSA=n.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41515

Affected Products

Caam
Op-Tee