PT-2026-69902 · Debian+3 · Optee Os
CVE-2026-71968
·
Published
2026-08-10
·
Updated
2026-08-25
CVSS v4.0
8.4
High
| Vector | AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
OP-TEE OS versions prior to 4.10.0 commit 8794043
Description
A use-after-free issue exists in the Trusted Application loader. Attackers capable of loading a signed Trusted Application can corrupt secure-world kernel memory by setting the
TA FLAG CONCURRENT flag in a user TA signed header. This allows two concurrent sessions to operate on the same shared context without locking, which corrupts the uctx->vm info.regions list during memref parameter mapping and unmapping. Consequently, vm region nodes still in use are freed, leading to a use-after-free in S-EL1 secure-world kernel memory.Recommendations
Update to the version containing commit 8794043.
Exploit
Fix
Use After Free
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Optee Os