SecMateSECMATE-2026-0018
VendorTrustedFirmware
Productoptee_os / SE050 crypto driver (NXP)
ClassificationMaintainer-classified bug
Timeline
Reported
Mar 5, 2026
Acknowledged
Mar 20, 2026
Published
Jul 20, 2026
Summary
In OP-TEE builds using the NXP SE050 crypto driver, a malicious or compromised Trusted Application can supply an RSA NOPAD input larger than the key modulus. An unchecked unsigned subtraction then causes attacker-controlled data to be written before a secure-world heap buffer, potentially corrupting the OP-TEE kernel heap or crashing the TEE. No complete attack chain from the normal world was demonstrated.