PatchSiren

OP-TEE CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH OP-TEE CVE published 2026-04-24

CVE-2026-33662

CVE-2026-33662 is a high-severity vulnerability in OP-TEE, a Trusted Execution Environment (TEE) for Arm Cortex-A cores. The vulnerability, caused by an integer underflow in the `emsa_pkcs1_v1_5_encode()` function, can lead to a remote denial-of-service (DoS) attack. The vulnerability affects OP-TEE versions from 3.8.0 to 4.10.0 and has a CVSS score of 7.5.

HIGH OP-TEE CVE published 2026-04-24

CVE-2026-33317

A high-severity vulnerability in OP-TEE, a Trusted Execution Environment (TEE) for Arm Cortex-A cores, allows for out-of-bounds read and write operations. This vulnerability, tracked as CVE-2026-33317, affects OP-TEE versions 3.13.0 through 4.10.0 and has a CVSS score of 8.7. The vulnerability is caused by missing checks in the `entry_get_attribute_value()` function in `ta/pkcs11/src/object.c`, which can [truncated]