What is CVE-2026-71967?
OP-TEE OS up to version 4.10.0 contains a null pointer dereference vulnerability in the Widevine pseudo-TA open_session handler. When CFG_WIDEVINE_PTA is enabled, Normal World clients can trigger a denial of service by opening a session directly on the Widevine PTA. The issue is fixed in commit 0aadfc2.
Azərbaycanca: OP-TEE OS 4.10.0-a qədər versiyalarda, Widevine pseudo-trusted application-nin open_session funksiyasında null pointer dereference zəifliyi mövcuddur. Bu, Normal World müştərilərinə CFG_WIDEVINE_PTA aktiv olduqda xidmət rəddinə səbəb olmağa imkan verir. Problemi aradan qaldırmaq üçün commit 0aadfc2 yaması tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-476
FAQ2
Which versions of OP-TEE OS are affected by CVE-2026-71967?
OP-TEE OS up to version 4.10.0 is affected by this vulnerability.
What condition is required to exploit CVE-2026-71967?
The CFG_WIDEVINE_PTA configuration option must be enabled.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.