


Perceptive Security
SOC/SIEM Consultancy

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology…
Published:
23 april 2026 om 22:00:00
Alert date:
24 april 2026 om 15:07:56
Source:
nvd.nist.gov
Operating Systems, Mobile & IoT
CVE-2026-33317 affects OP-TEE (Trusted Execution Environment) versions 3.13.0 through 4.10.0, specifically in the PKCS#11 Trusted Application component. The vulnerability stems from missing validation checks in the entry_get_attribute_value() function located in ta/pkcs11/src/object.c. This flaw can lead to out-of-bounds read operations from the PKCS#11 TA heap, potentially causing system crashes. When exploited through the PKCS11_CMD_GET_ATTRIBUTE_VALUE function with malicious template parameters, attackers can read up to 7 bytes beyond buffer boundaries and write beyond template buffer limits. The vulnerability has been addressed through three commits that will be included in version 4.11.0. Given OP-TEE's role as a security-critical component running on ARM TrustZone technology, this buffer overflow vulnerability poses significant risks to system integrity.
Technical details
Mitigation steps:
Affected products:
OP-TEE
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-33317
https://github.com/OP-TEE/optee_os/commit/149e8d7ecc4ef8bb00ab4a37fd2ccede6d79e1ca
https://github.com/OP-TEE/optee_os/commit/16926d5a46934c46e6656246b4fc18385a246900
https://github.com/OP-TEE/optee_os/commit/e031c4e562023fd9f199e39fd2e85797e4cbdca9
https://github.com/OP-TEE/optee_os/security/advisories/GHSA-8cqw-mg7v-c9p9
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
