Impact
The vulnerability is a null pointer dereference in the Widevine pseudo‑TA open_session handler of OP‑TEE OS through version 4.10.0. When the CFG_WIDEVINE_PTA option is enabled, a Normal World client can open a session on the Widevine PTA, causing the TEE to dereference a null calling session pointer via is_user_ta_ctx(). This results in a fault at the Secure EL1 level and crashes the trusted execution environment, effectively denying any functionality that depends on the TEE.
Affected Systems
OP‑TEE OS versions 4.10.0 and earlier that have the CFG_WIDEVINE_PTA configuration enabled are vulnerable; the issue is fixed in the commit 0aadfc2.
Risk and Exploitability
The CVSS score of 5.7 corresponds to moderate severity. EPSS data is not available, and the flaw is not listed in the CISA KEV catalog. The attack requires a local Normal World client to open a session on the vulnerable pseudo‑TA; no external network or elevated‑privilege conditions are described. Therefore the likelihood of exploitation depends largely on whether the vulnerable configuration is present and whether a local attacker can interact with the TEE.
OpenCVE Enrichment