๐Ÿ” CVE Alert

CVE-2026-71968

MEDIUM 6.7

OP-TEE OS 4.10.0 Use-After-Free via Trusted Application Loader TA_FLAG_CONCURRENT

CVSS Score
6.7
EPSS Score
0.0%
EPSS Percentile
0th

OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a use-after-free vulnerability in the Trusted Application loader that allows attackers with the ability to load a signed Trusted Application to corrupt secure-world kernel memory by setting the TA_FLAG_CONCURRENT flag in a user TA signed header. Attackers can cause two concurrent sessions to operate on the same shared context without locking, corrupting the uctx->vm_info.regions list during memref parameter mapping and unmapping to free vm_region nodes still in use, resulting in a use-after-free in S-EL1 secure-world kernel memory.

CWE CWE-416 CWE-362
Vendor op-tee
Product optee_os
Published Aug 10, 2026
Stay Ahead of the Next One

Get instant alerts for op-tee optee_os

Be the first to know when new medium vulnerabilities affecting op-tee optee_os are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

OP-TEE / optee_os
0 โ‰ค 4.10.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/OP-TEE/optee_os/pull/7900 github.com: https://github.com/OP-TEE/optee_os/commit/8794043c4065c26a2b8b1313794ba5ba5f06d296 vulncheck.com: https://www.vulncheck.com/advisories/op-tee-os-use-after-free-via-trusted-application-loader-ta-flag-concurrent

Credits

Argus Systems - ByteRay Ltd.