PT-2026-55977 · Op Tee · Op-Tee
CVSS v3.1
3.8
Low
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OP-TEE versions 3.0.0 through 4.10.x
Description
OP-TEE is a Trusted Execution Environment (TEE) designed as a companion to a non-secure Linux kernel running on Arm Cortex-A cores using TrustZone technology. A 32-bit integer overflow exists in the AES-GCM implementation of the OP-TEE core. This issue occurs when processing more than 512 megabytes of payload or Additional Authenticated Data (AAD), causing the authentication tag to be computed with incorrect bit-length values and breaking the authentication guarantee.
Recommendations
Update to version 4.11.0.
Fix
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Op-Tee