Malformed cryptographic attributes can corrupt OP-TEE secure-world kernel memory.
The PKCS#11 TA makes the driver path reachable from a normal-world client.
Affects
OP-TEE Core, the secure-world operating system used by embedded and mobile platforms, particularly builds using NXP CAAM; SE050 and Versal were listed as possibly affected, and follow-up review identified a HiSilicon HPRE path.
What it enables
Normal-world-triggered corruption of TEE-kernel stack or heap metadata
Attacker-controlled normal-world code opens a reachable Trusted Application such as the OP-TEE PKCS#11 TA→↓The client submits oversized cryptographic key attributes through the TEE Core API→↓Core validation permits inconsistent attribute sizes to reach a capacity-sensitive crypto backend→↓NXP CAAM right-aligns an oversized ECC value before its allocated buffer, or another backend copies oversized values into fixed-size storage→↓TEE-kernel stack or heap metadata is corrupted→↓Secure-world memory corruption is established, but repeatable control of OP-TEE kernel execution has not been demonstrated publicly.
Research leadExercise malformed key attributes through the PKCS#11 TA on CAAM and HiSilicon HPRE builds under secure-world instrumentation to determine whether overwritten metadata permits program-counter control.
Why this matters
Input accepted from a normal-world client crosses into secure-world kernel memory, and follow-up review found that the first repair did not cover another backend path.
Detail, proof-of-concept code and 2 sources
Required access
Normal-world client access to a Trusted Application accepting attacker-supplied cryptographic attributes; the PKCS#11 TA exposes the relevant Core APIs on affected configurations
Affected versions
>= 3.13.0
An attacker-controlled normal-world client can submit oversized RSA, DSA, DH, or ECC attributes through a reachable Trusted Application such as the PKCS#11 TA.
On NXP CAAM, an oversized ECC value is right-aligned before its allocated buffer after inconsistent sizing passes Core validation.
A September 28 follow-up identified analogous fixed-slot writes in HiSilicon HPRE, but that proposed repair closed on October 2 without merging.
Stack or heap corruption is established; repeatable control of secure-world kernel execution is not.
Evidence
The upstream advisory confirms that malformed attributes reach crypto drivers and corrupt stack or heap metadata from normal world through the PKCS#11 TA.TEE-kernel code execution was publicly demonstrated.The September 28 follow-up identified HiSilicon HPRE fixed-slot writes, but review exposed backend-specific representation problems and the PR was closed on October 2 without merging.
The same brief, every morning. One email a day, nothing else.
Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.