CVE-2026-33317 | OP-TEE optee_os up to 4.10.0 Trusted Execution Environment ta/pkcs11/src/object.c entry_get_attribute_value out-of-bounds (GHSA-8cqw-mg7v-c9p9)
A vulnerability categorized as critical has been discovered in OP-TEE optee_os up to 4.10.0. Affected is the function entry_get_attribute_value of the file ta/pkcs11/src/object.c of the component Trusted Execution Environment. Executing a manipulation can lead to out-of-bounds read.
This vulnerability appears as CVE-2026-33317. The attack requires local access. There is no available exploit.
Applying a patch is advised to resolve this issue.