CVE-2026-45702: OP-TEE has FF-A type confusion in SPMC tmem path that causes S-EL1 kernel panic
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 4.3.0 and prior to version 4.11.0, a type confusion vulnerability exists in OP-TEE OS when processing an FFAMEMSHARE request from the normal world. This only applies when OP-TEE is configured as an SPMC for S-EL0 SPs, that is, with CFGCORESEL1SPMC=y and CFGSECUREPARTITION=y. Version 4.11.0 fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
op-tee OSto a version that resolves this vulnerability.Fixed in 4.11.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45702?
The severity of CVE-2026-45702 is medium with a score of 4.4.
What causes the CVE-2026-45702 vulnerability?
CVE-2026-45702 is caused by a type confusion vulnerability in OP-TEE OS when processing an FFA_MEM_SHARE.
How do I fix CVE-2026-45702?
To fix CVE-2026-45702, you should upgrade OP-TEE OS to version 4.11.0 or later.
What is the impact of CVE-2026-45702 on systems?
CVE-2026-45702 can cause S-EL1 kernel panic in affected systems.
Which versions of OP-TEE OS are affected by CVE-2026-45702?
OP-TEE OS versions starting from 4.3.0 and prior to 4.11.0 are affected by CVE-2026-45702.