MEDIUMVulnerability
CVE-2026-71968
OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a use-after-free vulnerability in the Trusted Application loader that allows attackers with the ability to load a signed Trusted Application to corrupt secure-world kernel memory by setting the TA_FLAG_CONCURRENT flag in a user TA signed header. Attackers can cause two concurrent sessions to operate on the same shared context without locking, corrupting the uctx->vm_info.regions list during memref parameter mapping and unmapping to free vm_region nodes still in use, resulting in a use-after-free in S-EL1 secure-world kernel memory.
Properties
- severity
- MEDIUM
- score
- 6.7
- cve_id
- CVE-2026-71968
- vector
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- published_at
- 2026-08-10T19:17:32.263
- last_modified
- 2026-08-17T19:16:37.243
Related Entities (3)
HAS_WEAKNESS (2)
→[Weakness]Use After Free
→[Weakness]Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph