Executive brief
OP-TEE is a secure operating system used on Arm-based processors to protect sensitive data and cryptographic operations. A vulnerability in the Hisilicon HPRE hardware accelerator driver could allow an attacker to bypass encryption protections and recover sensitive information. By measuring the time it takes for the system to process specific requests, an attacker can eventually decrypt data that should remain private.
Technical details
The RSA PKCS#1 v1.5 decryption implementation in the Hisilicon HPRE crypto driver (`hpre_rsa.c`) contains multiple distinguishable early-exit paths and uses non-constant-time operations. Specifically, the `rsaes_pkcs_v1_5_decode` function uses a variable-time separator scan and `memcmp()` for label hash verification, creating a timing side-channel. An attacker with local access to a TEE interface (such as a Trusted Application API) can perform adaptive chosen-ciphertext queries to measure these timing differences. By analyzing approximately 1000-2000 decryption requests, the attacker can exploit the padding oracle to recover the original RSA plaintext. The issue is fixed in version 4.11.0 by implementing constant-time checks and removing data-dependent branching.
Affected products
- OP-TEE optee_os >= 4.5.0, < 4.11.0
Timeline
- 2026-03-18: other: Vulnerability discovered
- 2026-03-21: other: Security issue and severity confirmed
- 2026-06-18: patched: Fix published
- 2026-07-06: advisory: NVD advisory published