CVE-2026-71969 | OP-TEE OS up to 4.10.0 mbedTLS software backend RSA NOPAD Encrypt/RSA NOPAD Decrypt src_len/rsa_len heap-based overflow (EUVD-2026-55699)
A vulnerability was found in OP-TEE OS up to 4.10.0 and classified as very critical. This affects the function RSA NOPAD Encrypt/RSA NOPAD Decrypt of the component mbedTLS software backend. The manipulation of the argument src_len/rsa_len results in heap-based buffer overflow.
This vulnerability is identified as CVE-2026-71969. The attack can be executed remotely. There is not any exploit available.
It is best practice to apply a patch to resolve this issue.VulDB Recent EntriesRead More