trustedfirmware
Security Productscommercial
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting trustedfirmware.
- CVE-2026-53763OP-TEE has AES-GCM 32-bit integer overflow in length counters that breaks authentication guarantee3.8
- CVE-2026-44362OP-TEE's subkey rollback protection can be bypassed with older subkey versions5.5
- CVE-2026-42546OP-TEE has missing OPTEE_MSG_ATTR_TYPE_MASK in cleanup_shm_refs() leaks mobj references3.8
- CVE-2026-41516OP-TEE: Hisilicon HPRE PKCS#1 v1.5 Decryption Padding Oracle2.5
- CVE-2026-41515OP-TEE: RSA-OAEP padding oracle in NXP CAAM driver enables plaintext recovery2.5
- CVE-2026-41514OP-TEE: RSA-OAEP padding oracle in Hisilicon HPRE driver enables plaintext recovery2.5
- CVE-2026-41434OP-TEE has unbounded recursion in sanitize_client_object()3.3
- CVE-2026-40257OP-TEE has SHA-3 accelerated finalize heap overflow5.5
- CVE-2026-45702OP-TEE has FF-A type confusion in SPMC tmem path that causes S-EL1 kernel panic4.4
- CVE-2026-45614OP-TEE vulnerable to ECDH private key recovery4.7
- CVE-2026-40290OP-TEE has a Use-After-Free race in FF-A shared-memory teardown7.8
- CVE-2026-33662OP-TEE: RSASSA EMSA- PKCS1-v1_5 underflow in emsa_pkcs1_v1_5_encode()7.5
- CVE-2026-33317OP-TEE: PKCS#11 TA out-of-bounds read and memory disclosure8.7
- CVE-2026-34876An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows attackers to obtain adjacent CCM context data via invocatio...7.5
- CVE-2026-34877An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or session structures allows an attacker who can modify the s...9.8