Actually, the fix is included in tos image so that you can just update tos image rather than UEFI binary.
You have to refer to the steps in atf_and_optee_README.txt which would instruct you how to build tos image.
There’s a necessary step as following before building OP-TEE.
$ export UEFI_STMM_PATH=<UEFI source>/images/uefi_StandaloneMmOptee_RELEASE.bin