Executive brief
OP-TEE is a secure operating system used on ARM-based devices to protect sensitive data and perform secure operations. A flaw in how it manages shared memory allows a local attacker to trigger a race condition that could lead to memory corruption or the exposure of sensitive information within the secure environment. This could potentially allow an attacker to bypass security protections or gain unauthorized access to protected data.
Technical details
A use-after-free (UAF) race condition exists in the FF-A shared memory teardown logic within OP-TEE SPMC/SP flows when configured with CFG_SECURE_PARTITION=y. The vulnerability is caused by the function `sp_mem_remove()` failing to acquire the global `sp_mem_lock` before freeing entries in `smem->receivers` and `smem->regions`. Simultaneously, other threads executing `sp_mem_get_receiver()` or `sp_mem_is_shared()` may iterate over these lists without adequate synchronization. An attacker can exploit this race by triggering memory relinquishment or reclamation via FF-A calls, causing the secure world to dereference pointers to memory that has already been freed. This can result in secure world memory corruption or the leakage of sensitive data from freed objects. The issue is fixed in version 4.11.0.
Affected products
- Linaro OP-TEE OS 3.16.0 to 4.10.0
Timeline
- 2026-03-06: patched: Internal patch developed by maintainers.
- 2026-05-25: advisory: GitHub security advisory published.
- 2026-06-03: disclosed: CVE published to NVD.