What is CVE-2026-71968?
CVE-2026-71968 is a use-after-free vulnerability in the Trusted Application loader of OP-TEE OS up to version 4.10.0. Attackers with the ability to load a signed Trusted Application can corrupt secure-world kernel memory by setting the TA_FLAG_CONCURRENT flag. Updating to the version fixed in commit 8794043 is strongly recommended.
Azərbaycanca: CVE-2026-71968 OP-TEE OS-un 4.10.0 versiyasına qədər olan versiyalarında, etibarlı tətbiq yükləyicisində use-after-free zəifliyidir. İmzalanmış etibarlı tətbiqi yükləmək imkanı olan hücumçu TA_FLAG_CONCURRENT bayrağını istifadə edərək təhlükəsiz dünya kernel yaddaşını korlaya bilər. Ən qısa zamanda commit 8794043 ilə düzəldilmiş versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-416
FAQ2
What does an attacker need to do to exploit CVE-2026-71968?
The attacker must have the ability to load a signed Trusted Application on OP-TEE OS versions up to 4.10.0 and set the TA_FLAG_CONCURRENT flag.
How is CVE-2026-71968 mitigated?
Updating to the version fixed in commit 8794043 is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.