Executive brief
OP-TEE is a secure operating system used on Arm-based devices to protect sensitive data and perform secure operations away from the main Linux kernel. A flaw in how it handles memory sharing requests allows a high-privilege attacker in the normal operating system to crash the secure environment. This results in a system-wide denial of service, potentially disrupting secure boot, cryptographic services, or hardware-level security features.
Technical details
A type confusion vulnerability (CWE-843) exists in OP-TEE OS when processing an FFA_MEM_SHARE request from the normal world. When a request uses a dynamically allocated buffer, the system incorrectly passes a pointer to that buffer to the 'spmc_sp_add_share' function as if it were a 'struct ffa_rxtx' pointer. This allows an attacker with EL1 (kernel) privileges in the normal world to control memory addresses dereferenced by the secure world (S-EL1). The primary impact is a kernel panic in the OP-TEE core, causing a denial of service. This issue specifically affects configurations where OP-TEE acts as an SPMC for S-EL0 Secure Partitions (CFG_CORE_SEL1_SPMC=y and CFG_SECURE_PARTITION=y).
Affected products
- Linaro OP-TEE OS 4.3.0 to 4.10.0
Timeline
- 2026-02-23: disclosed: Report received by maintainers
- 2026-05-23: patched: Fix and advisory published on GitHub
- 2026-06-03: advisory: NVD publication date