What is CVE-2026-71969?
CVE-2026-71969 is a buffer underwrite vulnerability in the RSA NOPAD encrypt and decrypt operations within the mbedTLS software backend and SE050 hardware driver in OP-TEE OS through version 4.10.0. It allows a malicious Trusted Application to corrupt secure-world heap memory. Affected systems should be updated to the fixed commit 7b8b494 or later.
Azərbaycanca: CVE-2026-71969 OP-TEE OS 4.10.0 versiyasına qədər olan sistemlərdə, mbedTLS proqram arxa planı və SE050 aparat sürücüsündəki RSA NOPAD şifrələmə/şifrə açma əməliyyatlarında tapılan buffer underwrite zəifliyidir. Bu, zərərli Trusted Application-ın təhlükəsiz-world heap yaddaşını korlamağa imkan verir. Təsirlənən qurğular üçün commit 7b8b494 ilə təmin edilmiş yeniləmə tətbiq olunmalıdır.
Related CVEs
link basis: same weakness class CWE-787
FAQ2
Which versions of OP-TEE OS are affected by CVE-2026-71969?
CVE-2026-71969 affects OP-TEE OS through version 4.10.0.
Which update is required to fix CVE-2026-71969?
The fix for this vulnerability is included in commit 7b8b494 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.