| BDSA-2026-8419 |
|
Medium |
Apr 28, 2026 |
OP-TEE is vulnerable to memory corruption due to out-of-bounds reads and writes in the `entry_get_attribute_value` function. This could allow a local a
more...
OP-TEE is vulnerable to memory corruption due to out-of-bounds reads and writes in the `entry_get_attribute_value` function. This could allow a local attacker to trigger a denial-of-service (DoS) condition, or leverage the memory corruption in order to achieve more severe confidentiality, integrity or availability impacts.
less...
|
|
| BDSA-2026-8414 |
|
Medium |
Apr 28, 2026 |
OP-TEE is vulnerable to integer overflow due to improper handling of padding size calculations in the `emsa_pkcs1_v1_5_encode` function. This could all
more...
OP-TEE is vulnerable to integer overflow due to improper handling of padding size calculations in the `emsa_pkcs1_v1_5_encode` function. This could allow a remote attacker to trigger a denial-of-service (DoS).
less...
|
|
| BDSA-2026-13335 |
|
Medium |
Jun 04, 2026 |
OP-TEE is vulnerable to private key recovery due to insufficient public key validation. A local authenticated attacker could exploit this by supplying
more...
OP-TEE is vulnerable to private key recovery due to insufficient public key validation. A local authenticated attacker could exploit this by supplying crafted public keys, which could allow for the reconstruction of private keys.
less...
|
|
| BDSA-2026-13334 |
|
Low |
Jun 04, 2026 |
OP-TEE is vulnerable to type confusion due to improper handling of dynamically allocated buffers in the `FFA_MEM_SHARE` request when configured as an S
more...
OP-TEE is vulnerable to type confusion due to improper handling of dynamically allocated buffers in the `FFA_MEM_SHARE` request when configured as an SPMC for S-EL0 SPs. This could allow a local attacker to trigger a denial-of-service (DoS) by sending a maliciously crafted request.
**Note:** The vendor has stated that this issue only applies when the application has been configured as an SPMC for S-EL0 SPs with `CFG_CORE_SEL1_SPMC=y` and `CFG_SECURE_PARTITION=y`.
less...
|
|