Null Pointer Dereference Vulnerability in OP-TEE OS by Linaro
CVE-2026-71967

5.7MEDIUM

Key Information:

Vendor

Op-tee

Status
Vendor
CVE Published:
10 August 2026

What is CVE-2026-71967?

The OP-TEE OS, up to version 4.10.0, contains a vulnerability that results in a null pointer dereference in the Widevine pseudo-TA's open_session handler. When the CFG_WIDEVINE_PTA option is enabled, malicious entities can exploit this flaw by opening a session directly on the Widevine PTA. This triggers an unconditional dereference of a NULL session pointer through the is_user_ta_ctx() function, leading to a fault in the Trusted Execution Environment (TEE) at the S-EL1 security level and causing a denial of service. The issue has been addressed in a subsequent patch.

Affected Version(s)

optee_os 0 <= 4.10.0

optee_os 0 <= 4.10.0

optee_os 0aadfc23407f50e770eb5ddd871fc208f5626833

References

CVSS V4

Score:
5.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Argus Systems - ByteRay Ltd.
.