CVE-2026-33662General(trustedfirmware / op-tee)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. From 3.8.0 to 4.10, in the function emsa_pkcs1_v1_5_encode() in core/drivers/crypto/crypto_api/acipher/rsassa.c, the amount of padding needed, "PS size", is calculated by subtracting the size of the digest and other fields required for the EMA-PKCS1-v1_5 encoding from the size of the modulus of the key. By selecting a small enough modulus, this subtraction can overflow. The padding is added as a string of 0xFF bytes with a call to memset(), and an underflowed integer will cause the memset() call to overwrite until OP-TEE crashes. This only affects platforms registering RSA acceleration.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • op-tee

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-24); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
op-tee

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-24: 1Mentions · 2026-04-25: 1Technical Details · 2026-04-25: 104-2404-25
Signal classification2 categories
General
150.0%
Disclosure
150.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-241
General1
2026-04-251
Disclosure1
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33662 Integer Overflow in OP-TEE RSA PKCS1 v1.5 Encoding Versions 3.8.0... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33662 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The tweet points to CVE‑2026‑33662 with a brief technical description of an integer overflow in OP‑TEE RSA PKCS1 v1.5 encoding, but contains no PoC, exploit, or patch details.

    0000048
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-33662 OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. From… https://www.cve.org/CVERecord?id=CVE-2026-33662

    Post summary

    The snippet merely references CVE-2026-33662 with a short description and a link, offering no actionable or detailed information.

    00000102
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OStrustedfirmwareop-tee---

Explore more