CVE-2026-71967: NULL Pointer Dereference in OP-TEE optee_os
OP-TEE OS through 4.10.0, fixed in commit 0aadfc2, contains a null pointer dereference vulnerability in the Widevine pseudo-TA open_session handler that allows Normal World clients to cause a denial of service when CFG_WIDEVINE_PTA is enabled. Attackers can open a session directly on the Widevine PTA to trigger an unconditional dereference of a NULL calling session pointer via is_user_ta_ctx(), faulting the TEE at S-EL1 and crashing the trusted execution environment.
AI Analysis
Technical Summary
OP-TEE OS through version 4.10.0 contains a null pointer dereference vulnerability in the Widevine pseudo-TA open_session handler. When CFG_WIDEVINE_PTA is enabled, Normal World clients can open a session directly on the Widevine PTA, causing an unconditional dereference of a NULL calling session pointer via the is_user_ta_ctx() function. This results in a fault at the S-EL1 exception level and crashes the trusted execution environment, leading to a denial of service condition. The vulnerability is addressed in commit 0aadfc2.
Potential Impact
Exploitation of this vulnerability allows an attacker with limited privileges (Normal World client with low privileges) to cause a denial of service by crashing the trusted execution environment. There is no indication of code execution or data disclosure. The impact is limited to service disruption.
Mitigation Recommendations
A fix is available in OP-TEE OS in the commit identified as 0aadfc2. Users should update to a version that includes this commit to remediate the vulnerability. Patch status is not explicitly confirmed in the provided data, so users should verify with the OP-TEE vendor advisory for the exact fixed version and apply the official patch accordingly.
CVE-2026-71967: NULL Pointer Dereference in OP-TEE optee_os
Description
OP-TEE OS through 4.10.0, fixed in commit 0aadfc2, contains a null pointer dereference vulnerability in the Widevine pseudo-TA open_session handler that allows Normal World clients to cause a denial of service when CFG_WIDEVINE_PTA is enabled. Attackers can open a session directly on the Widevine PTA to trigger an unconditional dereference of a NULL calling session pointer via is_user_ta_ctx(), faulting the TEE at S-EL1 and crashing the trusted execution environment.
CVSS v4.0
Score 5.7medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
OP-TEE OS through version 4.10.0 contains a null pointer dereference vulnerability in the Widevine pseudo-TA open_session handler. When CFG_WIDEVINE_PTA is enabled, Normal World clients can open a session directly on the Widevine PTA, causing an unconditional dereference of a NULL calling session pointer via the is_user_ta_ctx() function. This results in a fault at the S-EL1 exception level and crashes the trusted execution environment, leading to a denial of service condition. The vulnerability is addressed in commit 0aadfc2.
Potential Impact
Exploitation of this vulnerability allows an attacker with limited privileges (Normal World client with low privileges) to cause a denial of service by crashing the trusted execution environment. There is no indication of code execution or data disclosure. The impact is limited to service disruption.
Mitigation Recommendations
A fix is available in OP-TEE OS in the commit identified as 0aadfc2. Users should update to a version that includes this commit to remediate the vulnerability. Patch status is not explicitly confirmed in the provided data, so users should verify with the OP-TEE vendor advisory for the exact fixed version and apply the official patch accordingly.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-08-08T16:43:04.178Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a7a1b7bbf8831d5395475fc
Added to database: 08/10/2026, 18:42:03 UTC
Last enriched: 08/10/2026, 18:59:19 UTC
Last updated: 09/04/2026, 10:52:11 UTC
Views: 42
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.