PT-2026-69902 · Debian+3 · Optee Os

CVE-2026-71968

·

Published

2026-08-10

·

Updated

2026-08-25

CVSS v4.0

8.4

High

VectorAV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions OP-TEE OS versions prior to 4.10.0 commit 8794043
Description A use-after-free issue exists in the Trusted Application loader. Attackers capable of loading a signed Trusted Application can corrupt secure-world kernel memory by setting the TA FLAG CONCURRENT flag in a user TA signed header. This allows two concurrent sessions to operate on the same shared context without locking, which corrupts the uctx->vm info.regions list during memref parameter mapping and unmapping. Consequently, vm region nodes still in use are freed, leading to a use-after-free in S-EL1 secure-world kernel memory.
Recommendations Update to the version containing commit 8794043.

Exploit

Fix

Use After Free

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71968

Affected Products

Optee Os