Executive brief
OP-TEE is a secure operating system used on Arm-based processors to protect sensitive data and cryptographic keys. A vulnerability in the NXP CAAM hardware driver allows an attacker to bypass certain encryption protections by measuring the time it takes for the system to process decryption requests. This could allow a malicious actor with local access to the system to eventually recover secret information that was supposed to remain encrypted.
Technical details
A timing side-channel vulnerability exists in the RSA-OAEP decryption implementation within the NXP CAAM crypto driver of OP-TEE. The root cause is the use of a non-constant-time `memcmp()` for label hash verification and a variable-time loop for finding the 0x01 separator byte. These distinguishable error paths create a Manger-style padding oracle. An attacker with the ability to submit chosen ciphertexts to a TEE interface (such as a Trusted Application) can recover the RSA-OAEP plaintext by observing response timing over approximately 1000-2000 queries. The issue is specific to NXP i.MX SoCs using the CAAM accelerator and is fixed in version 4.11.0 by implementing constant-time comparisons and unconditional buffer scanning.
Affected products
- OP-TEE optee_os >= 3.9.0, < 4.11.0
Timeline
- 2026-03-18: other: Vulnerability discovered
- 2026-04-17: patched: Fix reviewed and CVE requested
- 2026-06-18: advisory: GitHub advisory published
- 2026-07-06: disclosed: CVE published to NVD