3.3
CVE-2026-41434
- EPSS 0.11%
- Veröffentlicht 06.07.2026 17:24:40
- Zuletzt bearbeitet 07.07.2026 18:53:03
- CVE-Watchlists
- Unerledigt
OP-TEE has unbounded recursion in sanitize_client_object()
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.10.0 and prior to version 4.11.0, an unbounded recursion can crash the PKCS#11 TA. Version 4.11.0 contains a patch. No known workarounds are available.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trustedfirmware ≫ Op-tee Version >= 3.10.0 <= 4.10.0
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.11% | 0.013 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 3.3 | 1.8 | 1.4 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
|
CWE-121 Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
https://github.com/OP-TEE/optee_os/security/advisories/GHSA-wh38-23ff-grff