{"id":"CVE-2026-71967","summary":"OP-TEE OS 4.10.0 NULL Pointer Dereference DoS via Widevine PTA open_session","details":"OP-TEE OS through 4.10.0, fixed in commit 0aadfc2, contains a null pointer dereference vulnerability in the Widevine pseudo-TA open_session handler that allows Normal World clients to cause a denial of service when CFG_WIDEVINE_PTA is enabled. Attackers can open a session directly on the Widevine PTA to trigger an unconditional dereference of a NULL calling session pointer via is_user_ta_ctx(), faulting the TEE at S-EL1 and crashing the trusted execution environment.","modified":"2026-08-15T17:18:47.271329Z","published":"2026-08-10T18:11:01.124Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-476"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/71xxx/CVE-2026-71967.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/71xxx/CVE-2026-71967.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-71967"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/op-tee-os-null-pointer-dereference-dos-via-widevine-pta-open-session"},{"type":"REPORT","url":"https://github.com/OP-TEE/optee_os/pull/7899"},{"type":"FIX","url":"https://github.com/OP-TEE/optee_os/commit/0aadfc23407f50e770eb5ddd871fc208f5626833"},{"type":"PACKAGE","url":"https://github.com/OP-TEE/optee_os"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/op-tee/optee_os","events":[{"introduced":"0"},{"fixed":"753afbbee1682f5d16fd30e87b31058a4fd4f4b8"},{"fixed":"0aadfc23407f50e770eb5ddd871fc208f5626833"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"4.10.0"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["4.10.0","4.10.0-rc1","4.9.0","4.9.0-rc1","4.8.0","4.8.0-rc1","4.7.0","4.7.0-rc1","4.6.0","4.6.0-rc1","4.5.0","4.5.0-rc1","4.4.0","4.4.0-rc1","4.3.0","4.3.0-rc1","4.2.0","4.2.0-rc1","4.1.0","4.1.0-rc1","4.0.0","4.0.0-rc1","3.22.0","3.22.0-rc1","3.21.0","3.21.0-rc1","3.20.0","3.20.0-rc1","3.19.0","3.19.0-rc1","3.18.0","3.18.0-rc1","3.17.0","3.17.0-rc1","3.16.0","3.15.0","3.15.0-rc1","3.14.0","3.14.0-rc1","3.13.0","3.13.0-rc1","3.12.0","3.12.0-rc1","3.11.0","3.11.0-rc1","3.10.0","3.10.0-rc1","3.9.0","3.9.0-rc1","3.8.0","3.8.0-rc1","3.7.0","3.7.0-rc1","3.6.0","3.6.0-rc1","3.5.0","3.5.0-rc1","3.4.0","3.4.0-rc1","3.3.0","3.3.0-rc2","3.2.0","3.2.0-rc1","3.1.0","3.1.0-rc1","3.0.0","3.0.0-rc2","3.0.0-rc1","2.6.0","2.6.0-rc1","2.5.0","2.5.0-rc2","2.5.0-rc1","2.4.0","2.3.0","2.2.0","20160825-for-lmg","2.1.0","2.0.0","1.1.0","1.0.1","1.0.0","1.0.0-rc2","1.0.0-rc1","0.3.0","0.2.0","0.1.0"],"database_specific":{"vanir_signatures_modified":"2026-08-15T17:18:47Z","vanir_signatures":[{"digest":{"line_hashes":["112488651674395303960172839095137444515","300413817071004639452735836454770249184","308783664032164876628373890168517112932","135067116814026817076315052746175811748"],"threshold":0.9},"id":"CVE-2026-71967-6d8d7acb","signature_type":"Line","signature_version":"v1","source":"https://github.com/op-tee/optee_os/commit/0aadfc23407f50e770eb5ddd871fc208f5626833","target":{"file":"core/pta/widevine.c"},"deprecated":false}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-71967.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}