boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-71969HIGH
OP-TEE OS 4.10.0 Buffer Underwrite via RSA NOPAD Encrypt/Decrypt Operations
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   H   N   H   H   H    8.4   .0013    3.4     —
AFFECTED
  Product   Versions     Fixed
  optee_os  unspecified  7b8b494e0a324cefec8ed386b7de413b44f1aaf3
TIMELINE
  Aug 8   Reserved by VulnCheck
  Aug 9   EXPLOIT PUBLISHED — CVE-2026-71969 (OP-TEE optee_os). Public exploit reference added.
  Aug 10  Published (CNA: VulnCheck)
  Aug 13  EXPLOIT PUBLISHED — CVE-2026-71969 (OP-TEE optee_os). Public exploit reference added.
CWE-787, CWE-124 · CNA: VulnCheck · CVSS v4.0 · 5 references · NVD status: Received

Description

OP-TEE OS through 4.10.0, fixed in commit 7b8b494, contains a buffer underwrite vulnerability in the RSA NOPAD encrypt and decrypt operations within the mbedTLS software backend and SE050 hardware driver that allows a malicious Trusted Application to corrupt secure-world heap memory by supplying an input length exceeding the RSA modulus size. When src_len exceeds rsa_len, the subtraction expression wraps to a large unsigned value, causing a subsequent memcpy to write attacker-controlled data before the destination buffer in S-EL1 secure-world heap memory.

Lifecycle

Complete event history — 4 events, chronological
DateEventDetail
August 8, 2026ReservedReserved by VulnCheck
August 9, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2026-71969 (OP-TEE optee_os). Public exploit reference added.
August 10, 2026PublishedPublished (CNA: VulnCheck)
August 13, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2026-71969 (OP-TEE optee_os). Public exploit reference added.

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
OP-TEEoptee_os7b8b494e0a324cefec8ed386b7de413b44f1aaf3

Weaknesses

CWE-787 · CWE-124

References (5)

Related

Authoritative record: CVE-2026-71969 at cve.org

Vendors: op-tee

Weaknesses: CWE-787 · CWE-124

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-71969 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.