Summary
The OP-TEE set covers an RSA NOPAD heap underwrite, a trusted-application loader use-after-free, and a secure-world panic in the Widevine PTA. Argus also publishes CVE-2026-56101 for an inverted TKIP MIC-failure countermeasure test in OpenBSD.
Argus lists two affected OP-TEE paths for CVE-2026-71969. They are variants of one assigned vulnerability and count once.
Evidence boundary
The AI attribution is self-reported. The OP-TEE records have a direct CNA credit. CVE-2026-56101 remains visible because its technical disclosure is public, but its CVE publication status is explicitly weaker and should be rechecked in the next audit.
References
- Argus Proof of Possession
- CVE record: CVE-2026-71967
- CVE record: CVE-2026-71968
- CVE record: CVE-2026-71969
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.