CVE-2026-71967
OP-TEE OS 4.10.0 NULL Pointer Dereference DoS via Widevine PTA open_session
CVSS Score
5.5
EPSS Score
0.0%
EPSS Percentile
0th
OP-TEE OS through 4.10.0, fixed in commit 0aadfc2, contains a null pointer dereference vulnerability in the Widevine pseudo-TA open_session handler that allows Normal World clients to cause a denial of service when CFG_WIDEVINE_PTA is enabled. Attackers can open a session directly on the Widevine PTA to trigger an unconditional dereference of a NULL calling session pointer via is_user_ta_ctx(), faulting the TEE at S-EL1 and crashing the trusted execution environment.
| CWE | CWE-476 |
| Vendor | op-tee |
| Product | optee_os |
| Published | Aug 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for op-tee optee_os
Be the first to know when new medium vulnerabilities affecting op-tee optee_os are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected Versions
OP-TEE / optee_os
0 โค 4.10.0
References
Credits
Argus Systems - ByteRay Ltd.