CVE-2026-71968: OP-TEE OS 4.10.0 Use-After-Free via Trusted Application Loader TA_FLAG_CONCURRENT
OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a use-after-free vulnerability in the Trusted Application loader that allows attackers with the ability to load a signed Trusted Application to corrupt secure-world kernel memory by setting the TAFLAGCONCURRENT flag in a user TA signed header. Attackers can cause two concurrent sessions to operate on the same shared context without locking, corrupting the uctx->vminfo.regions list during memref parameter mapping and unmapping to free vmregion nodes still in use, resulting in a use-after-free in S-EL1 secure-world kernel memory.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OP-TEE OSto a version that resolves this vulnerability.Fixed in through 4.10.0Patch commit 8794043
Event History
Frequently Asked Questions
What is the severity of CVE-2026-71968?
CVE-2026-71968 has a medium severity rating of 6.7.
How do I fix CVE-2026-71968?
To fix CVE-2026-71968, update to OP-TEE OS version 4.10.1 or later, which resolves the vulnerability.
What type of vulnerability is CVE-2026-71968?
CVE-2026-71968 is identified as a use-after-free vulnerability caused by a race condition in the Trusted Application loader.
What are the potential impacts of CVE-2026-71968?
Exploitation of CVE-2026-71968 could allow attackers to corrupt secure-world kernel memory, potentially compromising the system's security.
Who is affected by CVE-2026-71968?
Users running OP-TEE OS versions up to 4.10.0 are affected by CVE-2026-71968.