CVE-2026-45702
- EPSS 0.16%
- Veröffentlicht 03.06.2026 17:55:18
- Zuletzt bearbeitet 05.06.2026 20:13:25
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 4.3.0 and prior to version 4.11.0, a type confusion vulnerability ex...
CVE-2026-45614
- EPSS 0.1%
- Veröffentlicht 03.06.2026 17:53:47
- Zuletzt bearbeitet 05.06.2026 20:21:19
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Prior to version 4.11.0, on many of the ECDH shared secret paths, the public key isn't v...
CVE-2026-40290
- EPSS 0.19%
- Veröffentlicht 03.06.2026 16:45:51
- Zuletzt bearbeitet 05.06.2026 20:20:54
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.16.0 and prior to 4.11.0, a user-after-free (UAF) race condition e...
CVE-2026-33662
- EPSS 0.4%
- Veröffentlicht 24.04.2026 18:13:28
- Zuletzt bearbeitet 05.06.2026 20:21:14
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. From 3.8.0 to 4.10, in the function emsa_pkcs1_v1_5_encode() in core/drivers/crypto/cryp...
CVE-2026-33317
- EPSS 0.18%
- Veröffentlicht 24.04.2026 02:20:55
- Zuletzt bearbeitet 05.06.2026 20:21:09
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. In versions 3.13.0 through 4.10.0, missing checks in `entry_get_attribute_value()` in `...
CVE-2023-41325
- EPSS 0.37%
- Veröffentlicht 15.09.2023 20:15:10
- Zuletzt bearbeitet 05.06.2026 20:13:25
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.20 and prior to version 3.22, `shdr_verify_signature` can make a d...
CVE-2022-47549
- EPSS 0.4%
- Veröffentlicht 19.12.2022 09:15:09
- Zuletzt bearbeitet 05.06.2026 20:13:25
An unprotected memory-access operation in optee_os in TrustedFirmware Open Portable Trusted Execution Environment (OP-TEE) before 3.20 allows a physically proximate adversary to bypass signature verification and install malicious trusted applications...
CVE-2022-46152
- EPSS 0.47%
- Veröffentlicht 29.11.2022 17:15:11
- Zuletzt bearbeitet 05.06.2026 20:23:06
OP-TEE Trusted OS is the secure side implementation of OP-TEE project, a Trusted Execution Environment. Versions prior to 3.19.0, contain an Improper Validation of Array Index vulnerability. The function `cleanup_shm_refs()` is called by both `entry_...
CVE-2021-44149
- EPSS 0.34%
- Veröffentlicht 07.12.2021 21:15:08
- Zuletzt bearbeitet 05.06.2026 20:13:25
An issue was discovered in Trusted Firmware OP-TEE Trusted OS through 3.15.0. The OPTEE-OS CSU driver for NXP i.MX6UL SoC devices lacks security access configuration for wakeup-related registers, resulting in TrustZone bypass because the NonSecure Wo...
CVE-2021-36133
- EPSS 0.26%
- Veröffentlicht 07.12.2021 21:15:08
- Zuletzt bearbeitet 05.06.2026 20:13:25
The OPTEE-OS CSU driver for NXP i.MX SoC devices lacks security access configuration for several models, resulting in TrustZone bypass because the NonSecure World can perform arbitrary memory read/write operations on Secure World memory. This involve...