Null Pointer Dereference Vulnerability in OP-TEE OS by Linaro
CVE-2026-71967
5.7MEDIUM
What is CVE-2026-71967?
The OP-TEE OS, up to version 4.10.0, contains a vulnerability that results in a null pointer dereference in the Widevine pseudo-TA's open_session handler. When the CFG_WIDEVINE_PTA option is enabled, malicious entities can exploit this flaw by opening a session directly on the Widevine PTA. This triggers an unconditional dereference of a NULL session pointer through the is_user_ta_ctx() function, leading to a fault in the Trusted Execution Environment (TEE) at the S-EL1 security level and causing a denial of service. The issue has been addressed in a subsequent patch.
Affected Version(s)
optee_os 0 <= 4.10.0
optee_os 0 <= 4.10.0
optee_os 0aadfc23407f50e770eb5ddd871fc208f5626833
