OP-TEE OS through 4.10.0, fixed in commit 0aadfc2, contains a null pointer dereference vulnerability in the Widevine pseudo-TA open_session handler that allows Normal World clients to cause a denial of service when CFG_WIDEVINE_PTA is enabled. Attackers can open a session directly on the Widevine PTA to trigger an unconditional dereference of a NULL calling session pointer via is_user_ta_ctx(), faulting the TEE at S-EL1 and crashing the trusted execution environment.
{
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-476"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/71xxx/CVE-2026-71967.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-71967.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"112488651674395303960172839095137444515",
"300413817071004639452735836454770249184",
"308783664032164876628373890168517112932",
"135067116814026817076315052746175811748"
],
"threshold": 0.9
},
"id": "CVE-2026-71967-6d8d7acb",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/op-tee/optee_os/commit/0aadfc23407f50e770eb5ddd871fc208f5626833",
"target": {
"file": "core/pta/widevine.c"
}
}
]
"2026-08-15T17:18:47Z"