OP-TEE
- Total products in the ecosystem
- 1
- Total vulnerabilities (90 days)
- 11
en
Verify to analyze this security profile
As of 09/14/2026, OP-TEE recorded 11 security vulnerabilities in the last 90 days across 1 products, including 2 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, optee_os had the most security vulnerabilities in the OP-TEE ecosystem, with 11 vulnerabilities—approximately 100% of the provider's total vulnerabilities during this period.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-71969OP-TEE OS 4.10.0 Buffer Underwrite via RSA NOPAD Encrypt/Decrypt Operations | Exploitation statusPublic exploit | FixYes | Affected productoptee_os | Published08/10/2026 | SeverityHigh |
CVE-2026-71968OP-TEE OS 4.10.0 Use-After-Free via Trusted Application Loader TA_FLAG_CONCURRENT | Exploitation statusNot known exploited | FixYes | Affected productoptee_os | Published08/10/2026 | SeverityHigh |
CVE-2026-71967OP-TEE OS 4.10.0 NULL Pointer Dereference DoS via Widevine PTA open_session | Exploitation statusNot known exploited | FixYes | Affected productoptee_os | Published08/10/2026 | SeverityMedium |
CVE-2026-53763OP-TEE has AES-GCM 32-bit integer overflow in length counters that breaks authentication guarantee | Exploitation statusNot known exploited | FixNot confirmed | Affected productoptee_os | Published07/06/2026 | SeverityLow |
CVE-2026-44362OP-TEE's subkey rollback protection can be bypassed with older subkey versions | Exploitation statusNot known exploited | FixNot confirmed | Affected productoptee_os | Published07/06/2026 | SeverityMedium |
CVE-2026-42546OP-TEE has missing OPTEE_MSG_ATTR_TYPE_MASK in cleanup_shm_refs() leaks mobj references | Exploitation statusNot known exploited | FixNot confirmed | Affected productoptee_os | Published07/06/2026 | SeverityLow |
CVE-2026-41516OP-TEE: Hisilicon HPRE PKCS#1 v1.5 Decryption Padding Oracle | Exploitation statusNot known exploited | FixNot confirmed | Affected productoptee_os | Published07/06/2026 | SeverityLow |
CVE-2026-41515OP-TEE: RSA-OAEP padding oracle in NXP CAAM driver enables plaintext recovery | Exploitation statusNot known exploited | FixNot confirmed | Affected productoptee_os | Published07/06/2026 | SeverityLow |
CVE-2026-41514OP-TEE: RSA-OAEP padding oracle in Hisilicon HPRE driver enables plaintext recovery | Exploitation statusNot known exploited | FixNot confirmed | Affected productoptee_os | Published07/06/2026 | SeverityLow |
CVE-2026-41434OP-TEE has unbounded recursion in sanitize_client_object() | Exploitation statusNot known exploited | FixNot confirmed | Affected productoptee_os | Published07/06/2026 | SeverityLow |
CVE-2026-40257OP-TEE has SHA-3 accelerated finalize heap overflow | Exploitation statusNot known exploited | FixNot confirmed | Affected productoptee_os | Published07/06/2026 | SeverityMedium |
CVE-2026-45702OP-TEE has FF-A type confusion in SPMC tmem path that causes S-EL1 kernel panic | Exploitation statusNot known exploited | FixNot confirmed | Affected productoptee_os | Published06/03/2026 | SeverityMedium |
CVE-2026-45614OP-TEE vulnerable to ECDH private key recovery | Exploitation statusPublic exploit | FixNot confirmed | Affected productoptee_os | Published06/03/2026 | SeverityMedium |
CVE-2026-40290OP-TEE has a Use-After-Free race in FF-A shared-memory teardown | Exploitation statusPublic exploit | FixNot confirmed | Affected productoptee_os | Published06/03/2026 | SeverityHigh |
CVE-2026-33662OP-TEE: RSASSA EMSA- PKCS1-v1_5 underflow in emsa_pkcs1_v1_5_encode() | Exploitation statusNot known exploited | FixNot confirmed | Affected productoptee_os | Published04/24/2026 | SeverityHigh |
CVE-2026-33317OP-TEE: PKCS#11 TA out-of-bounds read and memory disclosure | Exploitation statusNot known exploited | FixNot confirmed | Affected productoptee_os | Published04/24/2026 | SeverityHigh |
CVE-2025-46733REE userspace code can panic TAs, leading to fTPM PCR reset and data disclosure | Exploitation statusPublic exploit | FixYes | Affected productoptee_os | Published07/04/2025 | SeverityHigh |
CVE-2023-41325OP-TEE double free in shdr_verify_signature | Exploitation statusPublic exploit | FixYes | Affected productoptee_os | Published09/15/2023 | SeverityHigh |
CVE-2022-46152OP-TEE Trusted OS vulnerable to Improper Validation of Array Index in the cleanup_shm_refs function | Exploitation statusPublic exploit | FixNot confirmed | Affected productoptee_os | Published11/29/2022 | SeverityHigh |
CVE-2016-6129 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published02/13/2017 | SeverityUnknown |