CVE-2026-33317 affects OP-TEE in versions 3.13.0 through 4.10.0. The vulnerability is caused by missing bounds checks in entry_get_attribute_value() in ta/pkcs11/src/object.c. These missing validations can cause an out-of-bounds read from the PKCS#11 Trusted Application (TA) heap or trigger a crash. In addition, when this condition is chained with the out-of-bounds read, the PKCS#11 TA function PKCS11_CMD_GET_ATTRIBUTE_VALUE / entry_get_attribute_value() can be induced, via a malformed template parameter, to read up to 7 bytes past the end of the template buffer and write beyond the end of that template buffer using data taken from a PKCS#11 object attribute value.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
PKCS11_CMD_GET_ATTRIBUTE_VALUE. Where possible, limit creation or access to attacker-controlled PKCS#11 objects and templates, and monitor for crashes or anomalous behavior in the PKCS#11 TA. No complete mitigation short of patching is provided in the available content.Patch, then assume compromise.
e031c4e562023fd9f199e39fd2e85797e4cbdca9, 16926d5a46934c46e6656246b4fc18385a246900, and 149e8d7ecc4ef8bb00ab4a37fd2ccede6d79e1ca. If maintaining a downstream branch, backport these patches and verify that bounds checking around entry_get_attribute_value() and PKCS#11 template handling is present.1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a real proof-of-concept exploit for CVE-2026-33317 affecting the OP-TEE PKCS#11 Trusted Application. It is not a framework module; the main exploit is the standalone AArch64 C program c01_poc.c, supported by build_poc.sh, run_c01.sh, and the expect automation script c01_check.exp. The repository also includes documentation and captured logs proving successful reproduction. Core capability: the PoC uses libteec from the Normal World to open a session to the PKCS#11 TA (UUID fd02c9da-306c-48c7-a49c-bbd827ae86ee), initialize a token, open a PKCS#11 session, create an object with a controlled 16-byte CKA_LABEL, and then send a malformed CMD_GET_ATTRIBUTE_VALUE request. The crafted serialized template sets attrs_size=8 and attrs_count=1 while declaring an attribute size of 16, causing the TA to allocate a too-small temporary template buffer and then copy attribute data to an out-of-bounds pointer. The intended effect is Secure World heap corruption; the captured logs show allocator assertion failure and TA panic, so the practical demonstrated result is denial of service of the PKCS#11 TA with a memory corruption primitive that could potentially be developed further. Repository structure: c01_poc.c contains the exploit logic and raw TEEC command packing; build_poc.sh cross-compiles it for AArch64 against libteec; run_c01.sh launches a qemu_v8 OP-TEE lab and shares out/bin into the guest via virtio-9p; c01_check.exp automates guest login, mounting /mnt/host, running /mnt/host/c01_poc, and collecting logs. README.md, qemu-v8-setup.md, reproduction-log.md, and C-01-reproduction.md document the vulnerability, environment, and reproduction steps. out/bin/c01_nw.log and out/bin/c01_sw.log are captured proof logs showing the TA panic after exploitation. Notable endpoints/targets are mostly local lab artifacts rather than external C2 or remote infrastructure: the TA UUID, QEMU binary path, shared guest mount path, output logs, and advisory URLs. The exploit targets OP-TEE PKCS#11 TA versions prior to 4.11, with the reproduced vulnerable build identified as 4.10.0-rc1-7-g06c4e95e4 / commit 06c4e95e469c9c89e9ba4a6915d1be7bb8ea6fbc.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.