CVE-2026-41434: Trustedfirmware Op-Tee

Low severity, CVSS 3.3. EPSS: 0.2% chance of exploitation in the next 30 days.

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.10.0 and prior to version 4.11.0, an unbounded recursion can crash the PKCS#11 TA. Version 4.11.0 contains a patch. No known workarounds are available.

Affected products

Published 2026-07-06. Last modified 2026-07-07.