Executive brief
OP-TEE is a secure operating system used on ARM-based devices to protect sensitive data and perform secure operations. A flaw in its cryptographic components allows a malicious or malfunctioning application to crash the entire secure environment by overwriting its memory with zeros. This results in a total denial-of-service for all secure functions on the device, potentially requiring a full system reboot to recover.
Technical details
An off-by-one error exists in the `sha3_process()` function within `sha3_accel.c` when using ARMv8.2+ SHA3 Crypto Extensions (`CFG_CRYPTO_WITH_CE82=y`). The code uses a strict greater-than comparison (`>`) instead of greater-than-or-equal (`>=`) when checking input length against the block size. If a Trusted Application (TA) provides exactly one block of data, the internal `byte_index` is set to the block size without triggering hardware compression. During finalization in `sha3_done()`, an integer underflow occurs during a `memset` size calculation, resulting in a massive (~4GB) heap overflow of zeros. This corrupts TEE kernel memory and causes an immediate system crash. The vulnerability is fixed in version 4.11.0.
Affected products
- OP-TEE optee_os >= 3.21.0, < 4.11.0
Timeline
- 2026-03-13: other: Report received
- 2026-06-15: patched: Fix published
- 2026-06-15: advisory: GitHub advisory published
- 2026-07-06: disclosed: NVD publication