CVE-2026-71968
OP-TEE OS 4.10.0 Use-After-Free via Trusted Application Loader TA_FLAG_CONCURRENT
CVSS Score
6.7
EPSS Score
0.0%
EPSS Percentile
0th
OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a use-after-free vulnerability in the Trusted Application loader that allows attackers with the ability to load a signed Trusted Application to corrupt secure-world kernel memory by setting the TA_FLAG_CONCURRENT flag in a user TA signed header. Attackers can cause two concurrent sessions to operate on the same shared context without locking, corrupting the uctx->vm_info.regions list during memref parameter mapping and unmapping to free vm_region nodes still in use, resulting in a use-after-free in S-EL1 secure-world kernel memory.
| CWE | CWE-416 CWE-362 |
| Vendor | op-tee |
| Product | optee_os |
| Published | Aug 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for op-tee optee_os
Be the first to know when new medium vulnerabilities affecting op-tee optee_os are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Attack Vector
Local
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
OP-TEE / optee_os
0 โค 4.10.0
References
Credits
Argus Systems - ByteRay Ltd.