A vulnerability was found in OP-TEE OS up to 4.10.0 and classified as very critical. This affects the function
RSA NOPAD Encrypt/RSA NOPAD Decrypt of the component mbedTLS software backend. The manipulation of the argument src_len/rsa_len results in heap-based buffer overflow.
This vulnerability is identified as CVE-2026-71969. The attack can be executed remotely. There is not any exploit available.
It is best practice to apply a patch to resolve this issue.