Op-tee
31 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Op-tee, a product in the security products space. Use it to gauge the current risk picture and drill into individual advisories.
Op-tee CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 2 |
| 2026-05 | 0 |
| 2026-06 | 3 |
| 2026-07 | 8 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 31 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical7
- High10
- Medium8
- Low6
Latest CVEs
The 15 most recently published vulnerabilities affecting Op-tee.
- CVE-2026-53763OP-TEE has AES-GCM 32-bit integer overflow in length counters that breaks authentication guarantee3.8
- CVE-2026-44362OP-TEE's subkey rollback protection can be bypassed with older subkey versions5.5
- CVE-2026-42546OP-TEE has missing OPTEE_MSG_ATTR_TYPE_MASK in cleanup_shm_refs() leaks mobj references3.8
- CVE-2026-41516OP-TEE: Hisilicon HPRE PKCS#1 v1.5 Decryption Padding Oracle2.5
- CVE-2026-41515OP-TEE: RSA-OAEP padding oracle in NXP CAAM driver enables plaintext recovery2.5
- CVE-2026-41514OP-TEE: RSA-OAEP padding oracle in Hisilicon HPRE driver enables plaintext recovery2.5
- CVE-2026-41434OP-TEE has unbounded recursion in sanitize_client_object()3.3
- CVE-2026-40257OP-TEE has SHA-3 accelerated finalize heap overflow5.5
- CVE-2026-45702OP-TEE has FF-A type confusion in SPMC tmem path that causes S-EL1 kernel panic4.4
- CVE-2026-45614OP-TEE vulnerable to ECDH private key recovery4.7
- CVE-2026-40290OP-TEE has a Use-After-Free race in FF-A shared-memory teardown7.8
- CVE-2026-33662OP-TEE: RSASSA EMSA- PKCS1-v1_5 underflow in emsa_pkcs1_v1_5_encode()7.5
- CVE-2026-33317OP-TEE: PKCS#11 TA out-of-bounds read and memory disclosure8.7
- CVE-2023-41325OP-TEE double free in shdr_verify_signature7.4
- CVE-2022-47549An unprotected memory-access operation in optee_os in TrustedFirmware Open Portable Trusted Execution Environment (OP-TEE) before 3.20 allows a physically proximate adversary to bypass signature ve...6.4
Product grouping is registry-driven, with AI assist and human review. How it works