


Perceptive Security
SOC/SIEM Consultancy

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology…
Published:
2 June 2026 at 22:00:00
Alert date:
3 June 2026 at 19:01:16
Source:
nvd.nist.gov
Operating Systems, Mobile & IoT
OP-TEE Trusted Execution Environment versions 3.16.0 through 4.10.x contain a use-after-free race condition vulnerability in shared memory teardown logic. The vulnerability exists in the sp_mem_remove() function which fails to acquire proper locks before freeing memory entries. This affects OP-TEE when configured as SPMC for S-EL0 SPs with CFG_SECURE_PARTITION=y. Multiple code paths can access freed memory structures leading to use-after-free conditions. The issue is fixed in version 4.11.0.
Technical details
Mitigation steps:
Affected products:
OP-TEE
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-40290
https://github.com/OP-TEE/optee_os/security/advisories/GHSA-332c-xr93-849m
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
