These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A low-severity vulnerability was found in OP-TEE core's AES-GCM implementation. 32-bit integer overflows cause the authentication tag to be computed with incorrect bit-length values after processing more than 512 megabytes of payload or Additional Authenticated Data (AAD). This issue affects users of OP-TEE versions 3.0.0 through 4.10.0. The vulnerability was fixed in version 4.11.0. No workarounds are av [truncated]
A vulnerability in OP-TEE's subkey rollback protection allows the use of revoked or older subkey versions because the system fails to propagate versioning data during the Trusted Application (TA) loading process. This impacts OP-TEE mainline configurations that utilize subkey-based signing chains for Trusted Application (TA) authentication. The issue arises from a failure in propagating versioning data, s [truncated]
A resource leak vulnerability exists in OP-TEE, a Trusted Execution Environment (TEE) designed as a companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. The vulnerability is due to the function `cleanup_shm_refs()` in `core/tee/entry_std.c` failing to apply a required bitmask (`OPTEE_MSG_ATTR_TYPE_MASK`) to parameter attributes. This results in a persistent [truncated]
CVE-2026-41516 is a Bleichenbacher-style padding oracle vulnerability in the OP-TEE Hisilicon HPRE crypto driver. The issue affects OP-TEE versions from 4.5.0 up to but not including 4.11.0. An attacker can exploit this vulnerability to recover RSA PKCS#1 v1.5 plaintext. This vulnerability has a CVSS score of 2.5 and is rated as LOW. Organizations using OP-TEE versions between 4.5.0 and 4.10.0 should prio [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-06T20:16:32.060Z and has not been modified since then. This vulnerability affects OP-TEE versions between 3.9.0 and 4.10.0, allowing an attacker to recover RSA-OAEP plaintext with approximately 1000-2000 adaptive chosen ciphertext queries. The vulnerability is classified as a Manger-style padding or [truncated]
A low-severity vulnerability was found in OP-TEE, a Trusted Execution Environment (TEE) designed for Arm Cortex-A cores using TrustZone technology. The issue, tracked as CVE-2026-41434, allows an unbounded recursion that can crash the PKCS#11 TA. The vulnerability was introduced in version 3.10.0 and was patched in version 4.11.0. The vulnerability has a CVSS score of 3.3, indicating a low severity. Organ [truncated]
A heap overflow vulnerability exists in OP-TEE, a Trusted Execution Environment (TEE) designed for Arm-based systems, specifically affecting versions from 3.21.0 up to but not including 4.11.0. This issue arises from an off-by-one error in the ARM Crypto Extensions accelerated SHA-3 implementation. The vulnerability can lead to a massive heap overflow that corrupts all TEE kernel memory following the hash [truncated]
CVE-2026-33662 is a high-severity vulnerability in OP-TEE, a Trusted Execution Environment (TEE) for Arm Cortex-A cores. The vulnerability, caused by an integer underflow in the `emsa_pkcs1_v1_5_encode()` function, can lead to a remote denial-of-service (DoS) attack. The vulnerability affects OP-TEE versions from 3.8.0 to 4.10.0 and has a CVSS score of 7.5.
A high-severity vulnerability in OP-TEE, a Trusted Execution Environment (TEE) for Arm Cortex-A cores, allows for out-of-bounds read and write operations. This vulnerability, tracked as CVE-2026-33317, affects OP-TEE versions 3.13.0 through 4.10.0 and has a CVSS score of 8.7. The vulnerability is caused by missing checks in the `entry_get_attribute_value()` function in `ta/pkcs11/src/object.c`, which can [truncated]