AUGUST 22, 2026
Live Feed
Back to database
Case File

CVE-2026-40257

MEDIUM · CVSS 5.5 EPSS 0.11% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-06 · Last synced 2026-08-05

CyberRota Analysis

AI-Generated

The ARM Crypto Extensions in OP-TEE versions 3.21.0 to 4.10.0 are vulnerable to an off-by-one error that can lead to a significant heap overflow, potentially corrupting the entire TEE kernel memory. This issue affects all platforms configured with SHA3 Crypto Extensions enabled, posing a risk to systems utilizing these features. Organizations using OP-TEE in their Linux environments, particularly those on affected versions, should prioritize patching to version 4.11.0 or disabling the SHA3 Crypto Extensions as a workaround.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-40257
Severity
MEDIUM
CVSS
5.5
EPSS
0.11%
Linux

Original NVD Description

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.21.0 and prior to version 4.11.0, the ARM Crypto Extensions accelerated SHA-3 implementation has an off-by-one error that can cause a massive heap overflow that corrupts all TEE kernel memory following the hash state. This affects all platforms built with `CFG_CRYPTO_WITH_CE82=y` (ARMv8.2+ with SHA3 Crypto Extensions). Version 4.11.0 contains a patch. As a workaround, disable SHA3 Crypto Extensions with `CFG_CRYPTO_WITH_CE82=n`.

Related CVEs

Other vulnerabilities affecting the same vendor(s)