CVE-2026-41434

Description

A flaw was found in OP-TEE (Open Portable Trusted Execution Environment), a secure environment for Arm Cortex-A cores. This vulnerability allows a local attacker with low privileges to trigger an unbounded recursion within the PKCS#11 Trusted Application (TA). Successful exploitation could lead to a denial of service (DoS) by crashing the TA, impacting the availability of the system.

Statement

Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.

Understanding the Weakness (CWE)

Availability

Technical Impact: DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory); DoS: Amplification

An infinite loop will cause unexpected consumption of resources, such as CPU cycles or memory. The software's operation may slow down, or cause a long time to respond.

Frequently Asked Questions

Want to get errata notifications? Sign up here.