Metrics
Affected Vendors & Products
Tue, 11 Aug 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Op-tee
Op-tee op-tee Os |
|
| Vendors & Products |
Op-tee
Op-tee op-tee Os |
Mon, 10 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 10 Aug 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OP-TEE OS through 4.10.0, fixed in commit 0aadfc2, contains a null pointer dereference vulnerability in the Widevine pseudo-TA open_session handler that allows Normal World clients to cause a denial of service when CFG_WIDEVINE_PTA is enabled. Attackers can open a session directly on the Widevine PTA to trigger an unconditional dereference of a NULL calling session pointer via is_user_ta_ctx(), faulting the TEE at S-EL1 and crashing the trusted execution environment. | |
| Title | OP-TEE OS 4.10.0 NULL Pointer Dereference DoS via Widevine PTA open_session | |
| Weaknesses | CWE-476 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-10T21:10:24.782Z
Reserved: 2026-08-08T16:43:04.178Z
Link: CVE-2026-71967
Updated: 2026-08-10T18:59:16.740Z
Status : Received
Published: 2026-08-10T19:17:32.103
Modified: 2026-08-10T21:17:23.810
Link: CVE-2026-71967
No data.
OpenCVE Enrichment
Updated: 2026-08-11T14:00:14Z