Security-bulletin
Threads by month
- ----- 2025 -----
- July
- June
- May
- April
- March
- February
- January
- ----- 2024 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2023 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2022 -----
- December
- November
- October
- September
- August
- July
- June
- May
- 1 participants
- 37 discussions
发布于2025.07.01
备注:OpenHarmony 5.0阶段各分支中当前主要对OpenHarmony-5.0.3-Release分支进行安全漏洞维护。
OpenHarmony-4.1-Release分支当前已停止维护,后续这个分支的安全漏洞也不再维护,详情参见社区公告。 OpenHarmony-4.1-Release分支停止维护公告
CVE漏洞描述漏洞影响严重程度CVSS 3.1得分受影响的版本受影响的仓库修复链接
CVE-2025-24925applications_settings 内存泄露漏洞本地攻击者可造成DOS低危3.3OpenHarmony-v5.0.3-Releaseapplications_settings5.0.3.x
CVE-2025-27536arkcompiler_ets_runtime类型混淆漏洞本地攻击者可造成DOS低危3.3OpenHarmony-v5.0.3-Releasearkcompiler_ets_runtime5.0.3.x
CVE-2025-24298kernel_liteos_a UAF漏洞本地攻击者可造成DOS高危8.4OpenHarmony-v5.0.3-Releasekernel_liteos_a5.0.3.x
CVE-2025-27128kernel_liteos_a UAF漏洞本地攻击者可造成任意代码执行高危8.4OpenHarmony-v5.0.3-Releasekernel_liteos_a5.0.3.x
CVE-2025-26690communication_dsoftbus 空指针解引用漏洞本地攻击者可造成任意代码执行低危3.3OpenHarmony-v5.0.3-Releasecommunication_dsoftbus5.0.3.x
CVE-2025-25212distributeddatamgr_pasteboard 不当输入验证漏洞本地攻击者可造成DOS低危3.3OpenHarmony-v5.0.3-Releasedistributeddatamgr_pasteboard5.0.3.x
CVE-2025-27562communication_dsoftbus 内存泄露漏洞本地攻击者可造成DOS低危3.3OpenHarmony-v5.0.3-Releasecommunication_dsoftbus5.0.3.x
CVE-2025-24844communication_dsoftbus 内存泄露漏洞本地攻击者可造成DOS低危3.3OpenHarmony-v5.0.3-Releasecommunication_dsoftbus5.0.3.x
以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本,详细信息请参考三方公告。
CVE严重程度CVSS 3.1得分受影响的仓库受影响的OpenHarmony版本修复链接
CVE-2025-21999高危8.0kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-21926无尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-21785高危8.0kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-21776无尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-21764高危7.8kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-21762高危7.8kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2024-58058中危5.7kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2024-58020无尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2024-58009无尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2024-57981中危5.7kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2024-56720无尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2024-56571无尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2024-35823中危5.3kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2024-27032中危6.3kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2024-26982高危7.1kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2024-26960中危5.5kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2024-26886中危6.5kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2024-26779中危5.5kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2024-26759中危5.5kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2024-26747中危4.4kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2024-26671中危4.7kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2024-26665高危7.1kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2023-53118无尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2023-52653中危5.5kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2023-52619中危5.5kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2022-49897无尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2022-49630无尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2022-49443低危2.6kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2022-49135中危5.5kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2021-47558中危4.8kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2021-47432中危5.5kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2021-47182中危5.7kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
以下是各维护版本的安全补丁标签,请在合入当月及之前全部对应安全补丁之后,更新安全补丁标签。
对应维护版本安全补丁修改方式参考链接
5.0.3.xhttps://gitee.com/openharmony/startup_init/pulls/3905
1
0
发布于2025.06.03
备注:OpenHarmony 5.0阶段各分支中当前主要对OpenHarmony-5.0.3-Release分支进行安全漏洞维护。
OpenHarmony-4.1-Release分支当前已停止维护,后续这个分支的安全漏洞也不再维护,详情参见社区公告。 OpenHarmony-4.1-Release分支停止维护公告
CVE漏洞描述漏洞影响严重程度CVSS 3.1得分受影响的版本受影响的仓库修复链接
CVE-2025-20063arkui_ace_engine类型混淆漏洞本地攻击者可造成应用crash低危3.3OpenHarmony-v5.0.3-Releasearkui_ace_engine5.0.3.x
CVE-2025-21082arkui_ace_engine类型混淆漏洞本地攻击者可造成应用crash低危3.3OpenHarmony-v5.0.3-Releasearkui_ace_engine5.0.3.x
CVE-2025-23235arkcompiler_ets_runtime越界读漏洞本地攻击者可造成DOS低危3.3OpenHarmony-v5.0.3-Releasearkcompiler_ets_runtime5.0.3.x
CVE-2025-25217arkui_ace_engine空指针解引用漏洞本地攻击者可造成DOS低危3.3OpenHarmony-v5.0.3-Releasearkui_ace_engine5.0.3.x
CVE-2025-24493kernel_liteos_a条件竞争漏洞本地攻击者可造成敏感信息泄露中危5.5OpenHarmony-v5.0.3-Releasekernel_liteos_a5.0.3.x
CVE-2025-27131kernel_liteos_m不当输入验证漏洞本地攻击者可造成DOS中危6.1OpenHarmony-v5.0.3-Releasekernel_liteos_m5.0.3.x
CVE-2025-26691电话服务模块权限绕过漏洞本地攻击者可造成敏感信息泄露中危5.5OpenHarmony-v5.0.3-Releasetelephony_call_manager5.0.3.x
CVE-2025-26693security_access_token权限绕过漏洞本地攻击者可造成敏感信息泄露低危3.3OpenHarmony-v5.0.3-Releasesecurity_access_token5.0.3.x
CVE-2025-27563security_access_token权限绕过漏洞本地攻击者可造成敏感信息泄露低危3.3OpenHarmony-v5.0.3-Releasesecurity_access_token5.0.3.x
CVE-2025-27242安全组件管理模块不当输入验证本地攻击者可造成敏感信息泄露低危3.3OpenHarmony-v5.0.3-Releasesecurity_security_component_manager5.0.3.x
CVE-2025-27247剪切板模块权限绕过漏洞本地攻击者可造成敏感信息泄露中危5.5OpenHarmony-v5.0.3-Releasedistributeddatamgr_pasteboard5.0.3.x
以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本,详细信息请参考三方公告。
CVE严重程度CVSS 3.1得分受影响的仓库受影响的OpenHarmony版本修复链接
CVE-2025-21814中危5.7kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-21806中危4.6kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-21728中危5.5kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-21719无尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-21683中危5.5kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-21648无尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2024-58017无尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2024-57980中危5.5kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2024-57977低危2.6kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2024-57913中危4.7kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2024-57888无尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2024-57884无尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2024-35965无尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2024-27398中危4.6kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2023-53028中危5.5kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2022-49651无尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2022-49632中危4.7kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
以下是各维护版本的安全补丁标签,请在合入当月及之前全部对应安全补丁之后,更新安全补丁标签。
安全补丁标签链接
2025年06月[5.0.3.x]
1
0
发布于2025.04.01
备注:OpenHarmony 5.0阶段各分支中当前主要对OpenHarmony-5.0.2-Release分支进行安全漏洞维护, 部分仓已提前开始对OpenHarmony-5.0.3-Release分支进行维护。
CVE漏洞描述漏洞影响严重程度CVSS 3.1得分受影响的版本受影响的仓库修复链接
CVE-2025-22851kernel_liteos_a 整数溢出本地攻击者可在受限场景造成任意代码执行中危6.5OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Releasekernel_liteos_a5.0.2.x 4.1.x
CVE-2025-22842arkcompiler_ets_runtime越界读本地攻击者可造成DOS低危3.3OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x 4.1.x
CVE-2025-25057third_party_NuttX 内存泄露本地攻击者可造成DOS低危3.3OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Releasethird_party_NuttX5.0.2.x 4.1.x
CVE-2025-27534arkcompiler_ets_runtime越界读本地攻击者可造成DOS低危3.3OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x 4.1.x
CVE-2025-24304arkcompiler_ets_runtime越界写本地攻击者可造成DOS低危3.3OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x 4.1.x
CVE-2025-20102arkcompiler_ets_runtime越界读本地攻击者可造成DOS低危3.3OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x
CVE-2025-22452arkcompiler_ets_runtime越界读本地攻击者可造成DOS低危3.3OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x
以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本,详细信息请参考三方公告。
CVE严重程度CVSS 3.1得分受影响的仓库受影响的OpenHarmony版本修复链接
CVE-2024-57940中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.3-Release4.1.x 5.0.3.x
CVE-2024-57931无尚未提供kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.3-Release4.1.x 5.0.3.x
CVE-2024-57924无尚未提供kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.3-Release4.1.x 5.0.3.x
CVE-2024-57907高危7.1kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.3-Release4.1.x 5.0.3.x
CVE-2024-57874中危4.6kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.3-Release4.1.x 5.0.3.x
CVE-2024-57849中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.3-Release4.1.x 5.0.3.x
CVE-2024-57792中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.3-Release4.1.x 5.0.3.x
CVE-2024-56739中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.3-Release4.1.x 5.0.3.x
CVE-2024-56703中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.3-Release4.1.x 5.0.3.x
CVE-2024-56694中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.3-Release4.1.x 5.0.3.x
CVE-2024-56692中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.3-Release4.1.x 5.0.3.x
CVE-2024-56688中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.3-Release4.1.x 5.0.3.x
CVE-2024-56658高危7.8kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.3-Release4.1.x 5.0.3.x
CVE-2024-56647中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.3-Release4.1.x 5.0.3.x
CVE-2024-56644无尚未提供kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.3-Release4.1.x 5.0.3.x
CVE-2024-56633无尚未提供kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.3-Release4.1.x 5.0.3.x
CVE-2024-56606高危7.8kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.3-Release4.1.x 5.0.3.x
CVE-2024-56605高危7.8kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release4.1.x 5.0.2.x
CVE-2024-56601高危7.8kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.3-Release4.1.x 5.0.3.x
CVE-2024-56600高危7.8kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.3-Release4.1.x 5.0.3.x
CVE-2024-56583无尚未提供kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.3-Release4.1.x 5.0.3.x
CVE-2024-53194无尚未提供kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.3-Release4.1.x 5.0.3.x
CVE-2024-53174无尚未提供kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.3-Release4.1.x 5.0.3.x
CVE-2024-53173高危7.8kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.3-Release4.1.x 5.0.3.x
CVE-2024-53172无尚未提供kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.3-Release4.1.x 5.0.3.x
CVE-2024-53171高危7.8kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.3-Release4.1.x 5.0.3.x
CVE-2024-53168高危7.8kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.3-Release4.1.x 5.0.3.x
CVE-2024-47668中危4.7kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.3-Release4.1.x 5.0.3.x
CVE-2024-46715中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.3-Release4.1.x 5.0.3.x
CVE-2024-41055中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.3-Release4.1.x 5.0.3.x
CVE-2024-41013低危3.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.3-Release4.1.x 5.0.3.x
CVE-2024-35966无尚未提供kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.3-Release4.1.x 5.0.3.x
CVE-2024-35937低危3.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.3-Release4.1.x 5.0.3.x
CVE-2024-27388中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.3-Release4.1.x 5.0.3.x
CVE-2024-27047中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.3-Release4.1.x 5.0.3.x
CVE-2024-26878中危4.7kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release OpenHarmony-v5.0.3-Release4.1.x 5.0.2.x 5.0.3.x
CVE-2024-13176无尚未提供third_party_opensslOpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release4.1.x 5.0.2.x
CVE-2023-52501高危7.1kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release OpenHarmony-v5.0.3-Release4.1.x 5.0.2.x 5.0.3.x
CVE-2022-48816无尚未提供kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.3-Release4.1.x 5.0.3.x
CVE-2021-47200高危7.8kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.3-Release4.1.x 5.0.3.x
以下是各维护版本的安全补丁标签,请在合入当月及之前全部对应安全补丁之后,更新安全补丁标签。
安全补丁标签链接
2025年04月[5.0.2.x]
[4.1.x]
1
0
发布于2025.03.04
备注:OpenHarmony 5.0阶段各分支中当前仅对OpenHarmony-5.0.2-Release分支进行安全漏洞维护。
CVE漏洞描述漏洞影响CVSS3.1基础得分受影响的版本受影响的仓库修复链接
CVE-2025-0587arkcompiler_ets_runtime整数溢出漏洞本地攻击者可在受限场景造成任意代码执行3.8OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x 4.1.x
CVE-2025-23234arkcompiler_ets_runtime栈溢出漏洞本地攻击者可造成DOS3.3OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x 4.1.x
CVE-2025-21098liteos_a内核存在的权限绕过漏洞本地攻击者可造成信息泄露5.5OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Releasekernel_liteos_a5.0.2.x 4.1.x
CVE-2025-20042liteos_a内核越界读漏洞本地攻击者可造成信息泄露5.5OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Releasekernel_liteos_a5.0.2.x 4.1.x
CVE-2025-22443arkcompiler_ets_runtime越界读漏洞本地攻击者可造成DOS3.3OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x 4.1.x
CVE-2025-20021arkcompiler_ets_runtime越界读漏洞本地攻击者可造成DOS3.3OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x
CVE-2025-21089arkcompiler_ets_runtime越界读漏洞本地攻击者可造成DOS3.3OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x
CVE-2025-22897arkcompiler_ets_runtime栈溢出漏洞本地攻击者可造成DOS3.3OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x
CVE-2025-23420arkcompiler_ets_runtime越界写漏洞本地攻击者可造成DOS3.8OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x
CVE-2025-22835arkcompiler_ets_runtime越界写漏洞本地攻击者可造成DOS3.8OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x 4.1.x
CVE-2025-21084arkcompiler_ets_runtime空指针解引用漏洞本地攻击者可造成DOS3.8OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x
CVE-2025-22847arkcompiler_ets_runtime越界读漏洞本地攻击者可造成DOS3.3OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x
CVE-2025-23418arkcompiler_ets_runtime越界读漏洞本地攻击者可造成DOS3.3OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x 4.1.x
CVE-2025-20024arkcompiler_ets_runtime整数溢出漏洞本地攻击者可在受限场景造成任意代码执行3.8OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x
CVE-2025-21097arkcompiler_ets_runtime空指针解引用漏洞本地攻击者可造成DOS3.3OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x
CVE-2025-20081communication_dsoftbus UAF漏洞本地攻击者可在受限场景造成任意代码执行3.8OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Releasecommunication_dsoftbus5.0.2.x 4.1.x
CVE-2025-23409communication_dsoftbus UAF漏洞本地攻击者可在受限场景造成任意代码执行3.8OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Releasecommunication_dsoftbus5.0.2.x 4.1.x
CVE-2025-20091communication_dsoftbus UAF漏洞本地攻击者可在受限场景造成任意代码执行3.8OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Releasecommunication_dsoftbus5.0.2.x 4.1.x
CVE-2025-24301arkcompiler_ets_runtime UAF漏洞本地攻击者可在受限场景造成任意代码执行3.8OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x
CVE-2025-24309arkcompiler_ets_runtime越界写漏洞本地攻击者可在受限场景造成任意代码执行3.8OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x
CVE-2025-23414arkcompiler_ets_runtime UAF漏洞本地攻击者可在受限场景造成任意代码执行3.8OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x
CVE-2025-23240arkcompiler_ets_runtime越界写漏洞本地攻击者可在受限场景造成任意代码执行3.8OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x 4.1.x
CVE-2025-22837arkcompiler_ets_runtime空指针解引用漏洞本地攻击者可造成DOS3.3OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x 4.1.x
CVE-2025-20011communication_dsoftbus内存泄露漏洞本地攻击者可造成DOS3.3OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Releasecommunication_dsoftbus5.0.2.x 4.1.x
CVE-2025-20626arkcompiler_ets_runtime UAF漏洞本地攻击者可在受限场景造成任意代码执行3.8OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x
CVE-2025-22841arkcompiler_ets_runtime越界读漏洞本地攻击者可造成DOS3.3OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x
以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本,详细信息请参考三方公告。
CVE严重程度CVSS 3.1得分受影响的仓库受影响的OpenHarmony版本修复链接
CVE-2024-56756中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-56698中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-56670中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-56629中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-56616无尚未提供kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-56615高危7.8kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-56587中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-56586无尚未提供kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-56574中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-56569中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-53221中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-53218无尚未提供kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-53147无尚未提供kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-53144无尚未提供kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-53104中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-53099低危3.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
以下是各维护版本的安全补丁标签,请在合入当月及之前全部对应安全补丁之后,更新安全补丁标签。
安全补丁标签链接
2025年03月[5.0.2.x]
[4.1.x]
1
0
发布于2025.02.11
备注:OpenHarmony 5.0阶段各分支中当前仅对OpenHarmony-5.0.2-Release分支进行安全漏洞维护。
CVE漏洞描述漏洞影响CVSS3.1基础得分受影响的版本受影响的仓库修复链接
CVE-2025-0302liteos_a内核整数溢出漏洞本地攻击者可通过本漏洞造成DOS5.5OpenHarmony-v4.1-Releasekernel_liteos_a4.1.x
CVE-2025-0303liteos_a内核堆栈溢出漏洞本地攻击者可通过本漏洞获取root权限8.8OpenHarmony-v4.1-Releasekernel_liteos_a4.1.x
CVE-2025-0304liteos_a内核UAF漏洞本地攻击者可通过本漏洞获取root权限8.8OpenHarmony-v4.1-Releasekernel_liteos_a4.1.x
以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本,详细信息请参考三方公告。
CVE严重程度CVSS 3.1得分受影响的仓库受影响的OpenHarmony版本修复链接
CVE-2024-53142低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-53140低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-53125低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-53124中危4.7kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-53079低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-53068低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-53066低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-53063低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-53058中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-53054中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50304低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50302中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50301低危2.6kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50290高危8.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50268低危3.5kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50262高危8.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50258中危4.8kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-50256中危4.8kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-50237中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50195中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50194中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50192中危4.6kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50191中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50150高危7.1kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50142中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50135中危4.6kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50099中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50089低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50013中危5.7kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-49983高危8.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-49975中危5.7kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-49949中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-47660低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-46826中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-42098中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
以下是各维护版本的安全补丁标签,请在合入当月及之前全部对应安全补丁之后,更新安全补丁标签。
安全补丁标签链接
2025年02月[5.0.2.x]
[4.1.x]
1
0
发布于2025.01.07
备注:OpenHarmony 5.0阶段各分支中当前仅对OpenHarmony-5.0.2-Release分支进行安全漏洞维护。
CVE漏洞描述漏洞影响CVSS3.1基础得分受影响的版本受影响的仓库修复链接
CVE-2024-45070liteos_a内核越界读漏洞本地攻击者可通过本漏洞造成信息泄露5.5OpenHarmony-v4.1-Releasekernel_liteos_a4.1.x
CVE-2024-47398liteos_a内核越界写漏洞本地攻击者可通过本漏洞造成设备无法启动8.8OpenHarmony-v4.1-Releasekernel_liteos_a4.1.x
CVE-2024-54030软总线释放后使用漏洞本地攻击者可通过本漏洞造成DOS4.4OpenHarmony-v4.1-Releasecommunication_dsoftbus4.1.x
以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本,详细信息请参考三方公告。
CVE严重程度CVSS 3.1得分受影响的仓库受影响的OpenHarmony版本修复链接
CVE-2024-50154高危7.1kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50138高危8.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50131高危8.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50082中危5.7kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50067高危7.1kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50063低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50058低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50046低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50044中危4.8kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50038低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50036低危0.0kernel_linux_5.10OpenHarmony-v4.0-Release4.1.x
CVE-2024-50035低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50033低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50028低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50024低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50018高危8.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50015中危5.7kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50014中危4.8kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50010低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50006低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-49978中危5.7kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-49967中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-49960高危8.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-49959低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-49950中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-49948低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-49940中危4.8kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-49889低危0.0kernel_linux_5.10OpenHarmony-v4.0-Release4.1.x
CVE-2024-49884低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-49883低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-49882中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-49881低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-49859低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-49851中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-47742中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-47740中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-47738中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-47728低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-47726低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-47713中危4.6kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-47707中危4.8kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-47705中危5.7kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-47701高危7.1kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-47698高危8.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-47697高危8.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-47691高危7.1kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-47690中危4.6kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-47685中危4.3kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-47684低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-47679中危4.6kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-47678低危3.5kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-44986高危7.8kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2022-48975低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2022-48961低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
以下是各维护版本的安全补丁标签,请在合入当月及之前全部对应安全补丁之后,更新安全补丁标签。
安全补丁标签链接
2025年01月
[4.1.x]
1
0
发布于2024.11.05
备注:OpenHarmony-v4.0-Release分支已停止维护,后续这个分支的安全漏洞不再维护,详情参见:
OpenHarmony 4.0-Release分支停止维护公告
CVE漏洞描述漏洞影响CVSS3.1基础得分受影响的版本受影响的仓库修复链接
CVE-2024-47797liteos_a内核越界写漏洞本地攻击者可通过本漏洞获取root权限8.4OpenHarmony-v4.0-Release OpenHarmony-v4.1-Releasekernel_liteos_a4.0.x 4.1.x
CVE-2024-47404liteos_a内核内存二次释放漏洞本地攻击者可通过本漏洞获取root权限8.4OpenHarmony-v4.0-Release OpenHarmony-v4.1-Releasekernel_liteos_a4.0.x 4.1.x
CVE-2024-47137liteos_a内核越界写漏洞本地攻击者可通过本漏洞获取root权限8.4OpenHarmony-v4.0-Release OpenHarmony-v4.1-Releasekernel_liteos_a4.0.x 4.1.x
CVE-2024-47402liteos_a内核越界读漏洞本地攻击者可通过本漏洞造成DOS3.3OpenHarmony-v4.0-Release OpenHarmony-v4.1-Releasekernel_liteos_a4.0.x 4.1.x
以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本,详细信息请参考三方公告。
CVE严重程度CVSS 3.1得分受影响的仓库受影响的OpenHarmony版本修复链接
CVE-2024-8088高危7.5third_party_pythonOpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-45028中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-45006中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-44987高危7.8kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-43892中危4.7kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-43884中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-43882高危7.0kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-43871中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-43856中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-43853中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-43828中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-42312中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2024-42305高危8.0kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-42304中危5.7kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2024-42302高危7.8kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-42283中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-42276中危5.7kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-42271高危7.8kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-42106中危4.0kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2023-52889中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2023-52623中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2023-52615中危4.4kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2023-52622中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2023-52616中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2023-52886中危6.4kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2023-52679中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2023-52898中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-44969高危8.0kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2023-52635中危4.4kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2023-7013中危4.3web_webviewOpenHarmony-v4.1-Release4.1.x 4.1.x
CVE-2023-7012低危2.7web_webviewOpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.0.x 4.1.x 4.1.x
CVE-2023-7011中危4.3web_webviewOpenHarmony-v4.1-Release4.1.x
CVE-2023-7010低危2.7web_webviewOpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-6777中危4.3web_webviewOpenHarmony-v4.1-Release4.1.x
CVE-2024-6778低危3.1web_webviewOpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-3172高危8.8web_webviewOpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-3175中危6.3web_webviewOpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-6996低危3.1web_webviewOpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.0.x 4.1.x 4.1.x
CVE-2024-7004中危6.3web_webviewOpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-6989中危6.3web_webviewOpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-6119高危7.5third_party_opensslOpenHarmony-v4.0-Release4.0.x
CVE-2024-42292中危3.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-43834中危4.8kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-44952中危4.8kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-46798高危7.1kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-45018中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
如下是各维护版本的安全补丁标签,请在合入当月及之前全部对应安全补丁之后,更新安全补丁标签。
安全补丁标签链接
2024年11月[4.1.x]
[4.0.x]
1
0
发布于2024.10.08
CVE漏洞描述漏洞影响CVSS3.1基础得分受影响的版本受影响的仓库修复链接
CVE-2024-43696liteos_a内核内存泄露漏洞本地攻击者可通过本漏洞造成DOS3.3OpenHarmony-v4.0-Release OpenHarmony-v4.1-Releasekernel_liteos_a4.0.x 4.1.x
CVE-2024-43697liteos_a内核入参检测不完善漏洞本地攻击者可通过本漏洞造成DOS3.3OpenHarmony-v4.0-Release OpenHarmony-v4.1-Releasekernel_liteos_a4.0.x 4.1.x
CVE-2024-45382liteos_a内核越界写漏洞本地攻击者可通过本漏洞造成DOS3.3OpenHarmony-v4.0-Release OpenHarmony-v4.1-Releasekernel_liteos_a4.0.x 4.1.x
CVE-2024-39806liteos_a内核越界读漏洞本地攻击者可通过本漏洞造成信息泄露5.5OpenHarmony-v4.0-Release OpenHarmony-v4.1-Releasekernel_liteos_a4.0.x 4.1.x
CVE-2024-39831访问控制模块释放后使用漏洞本地攻击者取得高权限后可通过本漏洞造成任意代码执行4.4OpenHarmony-v4.1-Releasesecurity_access_token4.1.x
以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本,详细信息请参考三方公告。
CVE严重程度CVSS 3.1得分受影响的仓库受影响的OpenHarmony版本修复链接
CVE-2024-42236中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-42232中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-42229中危4.1kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-42226中危4.6kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-42161高危7.8kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-42160高危7.8kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-42154高危7.3kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-42115中危4.6kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-42114中危4.6kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-42084中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-42082中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-42068中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-41098中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-41087高危7.1kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-41072中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-41063中危4.8kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-41041低危2.6kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-41035中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-41020中危4.6kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-41012高危7.1kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-40971低危3.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-40961中危4.8kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-40960中危4.8kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-40959中危4.6kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-40942低危2.6kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-40912中危5.7kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-40905中危4.8kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-39509低危2.6kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-39501中危4.6kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-38615低危3.3kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-36031致命9.8kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-35947中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-35884中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-35235中危4.4third_party_cupsOpenHarmony-v4.1-Release4.1.x
CVE-2024-26984中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-26966中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2023-52672高危7.0kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-5496中危6.3web_webviewOpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-5843中危6.5web_webviewOpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-3168高危8.8web_webviewOpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-5840中危6.5web_webviewOpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-5839中危6.5web_webviewOpenHarmony-v4.1-Release4.1.x
CVE-2024-7000中危6.3web_webviewOpenHarmony-v4.1-Release4.1.x
CVE-2024-3170高危8.8web_webviewOpenHarmony-v4.0-Release4.0.x
CVE-2024-5846高危8.8web_webviewOpenHarmony-v4.1-Release4.1.x
CVE-2024-5844高危8.8web_webviewOpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-6291中危4.3web_webviewOpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-5499中危4.3web_webviewOpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-6992中危6.3web_webviewOpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
如下是各维护版本的安全补丁标签,请在合入当月及之前全部对应安全补丁之后,更新安全补丁标签。
安全补丁标签链接
2024年10月[4.1.x]
[4.0.x]
1
0
发布于2024.09.02
CVE漏洞描述漏洞影响CVSS3.1基础得分受影响的版本受影响的仓库修复链接
CVE-2024-28044liteos_a整数溢出漏洞本地攻击者可通过本漏洞造成crash3.3OpenHarmony-v4.0-Release OpenHarmony-v4.1-Releasekernel_liteos_a4.0.x 4.1.x
CVE-2024-41157liteos_a释放后使用漏洞本地攻击者可通过本漏洞获取root权限8.8OpenHarmony-v4.0-Release OpenHarmony-v4.1-Releasekernel_liteos_a4.0.x 4.1.x
CVE-2024-38386方舟eTS运行时越界读写漏洞本地攻击者通过本漏洞可在预装应用中执行代码8.4OpenHarmony-v4.0-Release OpenHarmony-v4.1-Releasearkcompiler_ets_runtime4.0.x 4.1.x
CVE-2024-39816方舟eTS运行时越界写漏洞本地攻击者通过本漏洞可在预装应用中执行代码8.4OpenHarmony-v4.0-Release OpenHarmony-v4.1-Releasearkcompiler_ets_runtime4.0.x 4.1.x
CVE-2024-39775网络管理权限绕过漏洞远程攻击者可通过本漏洞造成信息泄露6.5OpenHarmony-v4.0-Release OpenHarmony-v4.1-Releasecommunication_netmanager_base4.0.x 4.1.x
CVE-2024-41160liteos_a内核释放后使用漏洞本地攻击者可通过本漏洞获取root权限8.8OpenHarmony-v4.0-Release OpenHarmony-v4.1-Releasekernel_liteos_a4.0.x 4.1.x
CVE-2024-38382元能力权限绕过漏洞本地攻击者可通过本漏洞造成信息泄露5.5OpenHarmony-v4.0-Releaseability_ability_runtime4.0.x
CVE-2024-39612后台任务管理权限绕过漏洞本地攻击者可通过本漏洞造成信息泄露5.5OpenHarmony-v4.0-Releaseresourceschedule_background_task_mgr4.0.x
以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本,详细信息请参考三方公告。
CVE严重程度CVSS 3.1得分受影响的仓库受影响的OpenHarmony版本修复链接
CVE-2024-41009中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-41007低危3.3kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-39495高危7.1kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-39475中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-39472中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-39467低危2.6kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-39276中危4.8kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-38780中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-38601中危5.1kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-38596中危5.1kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-38588高危7.1kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-38577高危8.0kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-38564中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-36971高危7.8kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-36489中危5.7kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-36286中危4.8kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-36270中危4.8kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-34459中危5.5third_party_libxml2OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-34027中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-25739中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2024-24863中危5.3kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2024-24858中危4.6kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2024-24857中危4.6kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-22099中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2023-52791中危4.8kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2023-52498中危4.8kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x 4.0.x 4.0.x 4.0.x 4.0.x
CVE-2022-48810中危4.6kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2022-48809中危5.7kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2022-48805低危3.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2022-48804中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2021-47582中危4.6kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-5498中危6.3web_webviewOpenHarmony-v4.1-Release4.1.x
CVE-2024-5497低危0.0web_webviewOpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-5535中危5.9third_party_opensslOpenHarmony-v4.1-Release4.1.x
CVE-2024-5841高危8.8web_webviewOpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-5847高危8.8web_webviewOpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-24860中危4.6kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-26585中危4.7kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
如下是各维护版本的安全补丁标签,请在合入当月及之前全部对应安全补丁之后,更新安全补丁标签。
安全补丁标签链接
2024年09月[4.1.x]
[4.0.x]
1
0
发布于2024.08.06
以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本,详细信息请参考三方公告。
CVE严重程度CVSS 3.1得分受影响的仓库受影响的OpenHarmony版本修复链接
CVE-2024-3914低危3.6web_webviewOpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.0.x 4.1.x
CVE-2024-3843低危2.7web_webviewOpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-3841低危2.7web_webviewOpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-4671致命9.6web_webviewOpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-4603中危5.3third_party_opensslOpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-4761高危8.8web_webviewOpenHarmony-v4.0-Release4.0.x
CVE-2024-5274高危8.8web_webviewOpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-4947高危8.8web_webviewOpenHarmony-v4.0-Release4.0.x
CVE-2024-3840低危2.7web_webviewOpenHarmony-v4.1-Release4.1.x 4.1.x 4.1.x
CVE-2024-4331低危3.1web_webviewOpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.1.x
CVE-2024-4558低危3.1web_webviewOpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-5158低危2.7web_webviewOpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-3845低危2.7web_webviewOpenHarmony-v4.1-Release4.1.x 4.1.x
CVE-2024-35807中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-35978中危5.7kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-35950中危5.7kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-27431中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-35815低危3.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-5159中危4.7web_webviewOpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-5157低危0.0web_webviewOpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-36941中危5.7kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-36940中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-36939中危4.6kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-36938中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-36929中危5.7kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-36905中危4.6kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-36904高危7.1kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-36903中危4.8kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-36902中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-36901中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-36899高危7.1kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-36883低危3.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-36017低危3.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-36008中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-35997中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-35984中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-35969中危4.6kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-35962中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-35955中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-35910中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-35904中危5.7kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-35896低危2.6kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-35822低危3.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-35789中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-35785中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-28182中危5.3third_party_nghttp2OpenHarmony-v4.0-Release4.0.x
CVE-2024-27417中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-27414中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-27399中危5.3kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-27013中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-26934高危7.8kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-26805低危2.7kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2024-26801低危2.7kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2024-26735低危2.7kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2024-26733低危2.7kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2024-26601中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2023-52881低危3.7kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2023-52879低危2.7kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2023-52869低危2.7kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2023-52868低危2.7kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2023-52845中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2023-52835低危3.8kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2023-52832低危2.7kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2023-52803中危4.6kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2023-52781低危3.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2023-52756低危2.7kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2023-52739低危2.7kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2023-52730中危4.7kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2023-52462中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2023-52454中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2021-47469低危2.7kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
如下是各维护版本的安全补丁标签,请在合入当月及之前全部对应安全补丁之后,更新安全补丁标签。
安全补丁标签链接
2024年08月[4.1.x]
[4.0.x]
1
0
发布于2024.07.02
CVE漏洞描述漏洞影响严重 程度受影响的版本受影响的仓库修复链接
CVE-2024-31071方舟eTS运行时类型混淆漏洞本地攻击者通过本漏洞造成app crash低危OpenHarmony-v4.0-Releasarkcompiler_ets_runtime4.0.x
CVE-2024-37030方舟eTS运行时释放后使用漏洞远程攻击者通过本漏洞可在任意应用中执行代码高危OpenHarmony-v4.0-Releasarkcompiler_ets_frontend4.0.x
CVE-2024-36243方舟eTS运行时跨界内存读漏洞远程攻击者通过本漏洞可在任意应用中执行代码高危OpenHarmony-v4.0-Releasarkcompiler_ets_runtime4.0.x
CVE-2024-36278方舟eTS运行时类型混淆漏洞本地攻击者通过本漏洞造成app crash低危OpenHarmony-v4.0-Releasarkcompiler_ets_runtime4.0.x
CVE-2024-36260方舟eTS运行时跨界内存写漏洞远程攻击者通过本漏洞可在任意应用中执行代码高危OpenHarmony-v4.0-Releasarkcompiler_ets_runtime4.0.x
CVE-2024-37185方舟eTS运行时跨界内存写漏洞远程攻击者通过本漏洞可在任意应用中执行代码高危OpenHarmony-v4.0-Releasarkcompiler_ets_runtime4.0.x
CVE-2024-37077方舟eTS运行时跨界内存写漏洞远程攻击者通过本漏洞可在任意应用中执行代码高危OpenHarmony-v4.0-Releasarkcompiler_ets_runtime4.0.x
以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本
CVE严重程度CVSS 3.1 得分受影响的仓库受影响的OpenHarmony版本修复链接
CVE-2021-47474高危8.0kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2021-47479高危7.1kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2021-47483高危7.1kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2021-47485高危8.0kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2021-47506高危7.1kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2021-47521高危8.0kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2022-48655高危7.8kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2023-52467中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2024-26602中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2024-26852中危4.6kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-26862中危4.6kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2024-26883高危7.8kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-26884高危7.8kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-26885高危7.8kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-26901中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-26903中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-26923低危2.6kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-27004中危4.8kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-27038低危2.7kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-31755中危5.5third_party_cJSONOpenHarmony-v4.0-Release4.0.x
请在合入当月及之前全部已公开安全补丁之后,参考如下各维护版本的安全补丁标签更新方法,更新安全补丁标签至07月。
对应维护版本安全补丁修改方式参考链接
4.1.xhttps://gitee.com/openharmony/startup_init/pulls/2895
4.0.xhttps://gitee.com/openharmony/startup_init/pulls/2894
1
0
发布于2024.06.04
以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本
CVE严重程度CVSS 3.1 得分受影响的仓库受影响的OpenHarmony版本修复链接
CVE-2024-39417低危3.5third_party_mbedtlsOpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x
CVE-2024-2478中危4.9third_party_wpa_supplicantOpenHarmony-v4.0-Release4.0.x 4.1.x
CVE-2024-2398高危7.5third_party_curlOpenHarmony-v4.1-Release4.1.x
CVE-2024-2004中危5.3third_party_curlOpenHarmony-v4.1-Release4.1.x
CVE-2024-0450中危6.2third_party_pythonOpenHarmony-v4.0-Release4.0.x
CVE-2023-6597高危7.8third_party_pythonOpenHarmony-v4.0-Release4.0.x
CVE-2023-52474高危7.8kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2023-52160中危6.5third_party_wpa_supplicantOpenHarmony-v4.0-Release4.0.x
CVE-2022-21499中危6.7kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2022-2078中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2022-1012高危8.2kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2022-0854中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2021-4001中危4.1kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2021-33655中危6.7kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2024-1059高危8.8web_webviewOpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-1283高危9.8web_webviewOpenHarmony-v4.0-Release4.0.x
CVE-2024-0810高危7.8web_webviewOpenHarmony-v4.0-Release4.0.x
CVE-2024-0808中危4.3web_webviewOpenHarmony-v4.0-Release4.0.x
CVE-2024-2625高危8.8web_webviewOpenHarmony-v4.0-Release4.0.x
CVE-2024-1672中危6.1web_webviewOpenHarmony-v4.0-Release4.0.x
CVE-2024-0519高危8.8web_webviewOpenHarmony-v4.0-Release4.0.x
CVE-2024-0224高危8.8web_webviewOpenHarmony-v4.0-Release4.0.x 4.0.x
CVE-2024-1676中危4.3web_webviewOpenHarmony-v4.0-Release4.0.x
CVE-2024-0223高危8.8web_webviewOpenHarmony-v4.0-Release4.0.x
CVE-2024-1670高危8.6web_webviewOpenHarmony-v4.0-Release4.0.x
CVE-2024-0333中危5.3web_webviewOpenHarmony-v4.0-Release4.0.x
CVE-2024-1077高危8.8web_webviewOpenHarmony-v4.0-Release4.0.x
CVE-2024-0518高危8.8web_webviewOpenHarmony-v4.0-Release4.0.x
CVE-2024-0222高危8.8web_webviewOpenHarmony-v4.0-Release4.0.x
CVE-2024-0807高危8.8web_webviewOpenHarmony-v4.0-Release4.0.x 4.0.x
CVE-2024-3157高危8.1web_webviewOpenHarmony-v4.0-Release4.0.x
CVE-2024-3839中危6.5web_webviewOpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-3516高危8.8web_webviewOpenHarmony-v4.0-Release4.0.x
CVE-2024-3837高危8.8web_webviewOpenHarmony-v4.0-Release4.0.x
CVE-2024-3159高危8.8web_webviewOpenHarmony-v4.0-Release4.0.x
CVE-2023-5480中危6.1web_webviewOpenHarmony-v4.0-Release4.0.x
CVE-2023-6347高危8.8web_webviewOpenHarmony-v4.0-Release4.0.x
CVE-2023-6703高危8.8web_webviewOpenHarmony-v4.0-Release4.0.x
CVE-2023-6345高危9.6web_webviewOpenHarmony-v4.0-Release4.0.x
CVE-2023-6112高危8.8web_webviewOpenHarmony-v4.0-Release4.0.x
CVE-2023-5482高危8.8web_webviewOpenHarmony-v4.0-Release4.0.x 4.0.x 4.0.x
CVE-2023-7024高危8.8web_webviewOpenHarmony-v4.0-Release4.0.x
CVE-2023-6510高危8.8web_webviewOpenHarmony-v4.0-Release4.0.x
CVE-2023-6508高危8.8web_webviewOpenHarmony-v4.0-Release4.0.x
CVE-2023-5997高危8.8web_webviewOpenHarmony-v4.0-Release4.0.x
CVE-2023-6705高危8.8web_webviewOpenHarmony-v4.0-Release4.0.x
CVE-2023-6702高危8.8web_webviewOpenHarmony-v4.0-Release4.0.x
CVE-2023-5996高危8.8web_webviewOpenHarmony-v4.0-Release4.0.x
请在合入当月及之前全部已公开安全补丁之后,参考如下各维护版本的安全补丁标签更新方法,更新安全补丁标签至06月。
对应维护版本安全补丁修改方式参考链接
4.1.xhttps://gitee.com/openharmony/startup_init/pulls/2809
4.0.xhttps://gitee.com/openharmony/startup_init/pulls/2808
1
0
发布于2024.05.07
备注:OpenHarmony 3.2-Release分支已停止维护,后续该分支的安全漏洞也不再维护,详情参见: OpenHarmony 3.2-Release分支停止维护公告
CVE漏洞描述漏洞影响严重程度受影响的版本受影响的仓库修复链接
CVE-2024-27217MSDP释放后使用漏洞本地攻击者通过本漏洞可在预装应用中执行任意代码中危OpenHarmony-v4.0-Releasemsdp_device_status4.0.x
CVE-2024-23808Ark编译器前端越界读漏洞本地攻击者通过本漏洞可在预装应用中执行任意代码中危OpenHarmony-v4.0-Releasearkcompiler_ets_frontend4.0.x
CVE-2024-31078蓝牙服务释放后使用漏洞本地攻击者通过本漏洞造成服务crash低危OpenHarmony-v4.0-Releasecommunication_bluetooth_service4.0.x
CVE-2024-3757Ark运行时整数溢出漏洞本地攻击者通过本漏洞造成应用crash低危OpenHarmony-v4.0-Releasearkcompiler_ets_runtime4.0.x
CVE-2024-3758Hmdfs堆溢出漏洞本地攻击者通过本漏洞可在TCB中执行任意代码中危OpenHarmony-v4.0-Releasekernel_linux_5.104.0.x
CVE-2024-3759Hmdfs释放后使用漏洞本地攻击者通过本漏洞可在TCB中执行任意代码中危OpenHarmony-v4.0-Releasekernel_linux_5.104.0.x
以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本
CVE严重程度CVSS 3.1 得分受影响的仓库受影响的OpenHarmony版本修复链接
CVE-2024-26614中危5.3kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2024-26606低危3.5kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2024-26589高危7.8kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2023-6176中危4.7kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2023-6121中危4.3kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2023-52492中危5.7kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2023-52486中危4.8kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2023-52444高危7.8kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2023-52443中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2023-52438高危7.8kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2023-52435中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2023-51779中危4.6kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2021-46945中危5.7kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2021-33631高危7.8kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
请在合入当月及之前全部已公开安全补丁之后,参考如下各维护版本的安全补丁标签更新方法,更新安全补丁标签至05月。
对应维护版本安全补丁修改方式参考链接
4.0.xhttps://gitee.com/openharmony/startup_init/pulls/2728
1
0
发布于2024.04.02
CVE漏洞描述漏洞影响严重程度受影响的版本受影响的仓库修复链接
CVE-2024-21834Arkui类型混淆漏洞本地攻击者通过本漏洞造成app crash低危OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Releasearkui_ace_engine3.2.x
CVE-2024-22177Audio权限管理不当漏洞本地攻击者通过本漏洞造成app crash低危OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Releasemultimedia_audio_framework3.2.x
CVE-2024-22098AVSession释放后使用漏洞本地攻击者通过本漏洞可在任意应用中执行代码中危OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Releasemultimedia_av_session3.2.x
CVE-2024-22180Camera释放后使用漏洞本地攻击者通过本漏洞造成DOS低危OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Releasemultimedia_camera_framework3.2.x 4.0.x
CVE-2024-29074Telephony入参检测不完善漏洞本地攻击者通过本漏洞可在任意应用中执行代码中危OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Releasetelephony_cellular_call3.2.x 3.2.x
CVE-2024-22092包管理权限管理不当漏洞远程攻击者通过本漏洞绕过管控安装应用, 但需要本地用户的交互高危OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Releasebundlemanager_bundle_framework3.2.x
CVE-2024-24581方舟eTS运行时越界写漏洞本地攻击者通过本漏洞可在任意应用中执行代码中危OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Releasearkcompiler_ets_runtime3.2.x 4.0.x
CVE-2024-28226文件系统入参检测不完善漏洞远程攻击者通过本漏洞造成DOS高危OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Releasekernel_linux_5.103.2.x 4.0.x
CVE-2024-28951方舟eTS运行时释放后使用漏洞本地攻击者通过本漏洞可在预装应用中执行代码中危OpenHarmony-v4.0-Releasearkcompiler_ets_runtime4.0.x
CVE-2024-29086方舟eTS运行时栈溢出漏洞本地攻击者通过本漏洞造成DOS低危OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Releasearkcompiler_ets_runtime3.2.x
以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本
CVE严重程度CVSS 3.1 得分受影响的仓库受影响的OpenHarmony版本修复链接
CVE-2024-0641中危5.5kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
CVE-2022-48619中危5.5kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
CVE-2023-39197中危4.0kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
CVE-2024-0584中危5.5kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
CVE-2023-46343中危5.5kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
CVE-2024-23851中危5.5kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
CVE-2024-23850中危5.5kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
CVE-2024-23849中危5.5kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
CVE-2024-0639中危5.5kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
CVE-2024-0775高危7.1kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
CVE-2023-51043高危7.0kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
CVE-2023-52340高危7.5kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
CVE-2023-46838高危7.5kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
CVE-2022-2503中危6.7kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
CVE-2014-0069高危8.4kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
CVE-2024-1086高危7.8kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
CVE-2015-5157高危8.4kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
CVE-2021-46958高危7.8kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
CVE-2024-25062高危7.5third_party_libxml2OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
CVE-2024-24806致命9.8third_party_libuvOpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
CVE-2024-22195中危6.1third_party_jinja2OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
CVE-2024-0814中危6.5third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
CVE-2024-0810中危4.3third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
CVE-2023-6040高危7.8kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
请在合入当月及之前全部已公开安全补丁之后,参考如下各维护版本的安全补丁标签更新方法,更新安全补丁标签至04月。
对应维护版本安全补丁修改方式参考链接
3.2.xhttps://gitee.com/openharmony/startup_init/pulls/2633
4.0.xhttps://gitee.com/openharmony/startup_init/pulls/2632
1
0
发布于2024.03.04
CVE漏洞描述漏洞影响CVSS3.1得分受影响的版本受影响的仓库修复链接
CVE-2023-25176剪切板越界读漏洞本地攻击者通过本漏洞造成信息泄露2.9OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Releasedistributeddatamgr_pasteboard3.2.x
CVE-2023-46708WLAN UAF漏洞本地攻击者通过本漏洞可在任意应用中执行代码4.3OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Releasecommunication_wifi3.2.x
CVE-2023-49602Arkui 类型混淆漏洞本地攻击者通过本漏洞造成应用崩溃2.9OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Releasearkui_ace_engine3.2.x 3.2.x
CVE-2024-21816后台任务管理权限管理不当漏洞本地攻击者通过本漏洞绕过鉴权访问数据4.0OpenHarmony-v4.0-Releaseresourceschedule_background_task_mgr4.0.x
CVE-2024-21826密钥管理敏感信息泄露漏洞近场攻击者通过本漏洞造成敏感信息泄露4.3OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Releasesecurity_huks3.2.x
以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本
CVE严重程度CVSS 3.1 得分受影响的仓库受影响的OpenHarmony版本修复链接
CVE-2024-0519高危8.8third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
CVE-2024-0518高危8.8third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
CVE-2024-0333中危5.3third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
CVE-2024-0224高危8.8third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
CVE-2024-0223高危8.8third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
CVE-2024-0222高危8.8third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
CVE-2023-7192中危4.4kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
CVE-2023-7024高危8.8third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
CVE-2023-6531高危7.0kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2023-6112高危8.8third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
CVE-2023-5997高危8.8third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
CVE-2023-5996高危8.8third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
CVE-2023-5849高危8.8third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
CVE-2023-5717高危7.8kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2023-5482高危8.8third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
CVE-2023-5480中危6.1third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
CVE-2023-51782中危4.6kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
CVE-2023-51781中危4.6kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2023-51780中危4.6kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
CVE-2023-45897致命9.1third_party_exfatprogsOpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release3.2.x
CVE-2022-46908高危7.3third_party_sqliteOpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release3.2.x
CVE-2021-44879中危5.5kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release4.0.x 3.2.x
请在合入当月及之前全部已公开安全补丁之后,参考如下各维护版本的安全补丁标签更新方法,更新安全补丁标签至03月。
对应维护版本安全补丁修改方式参考链接
3.2.xhttps://gitee.com/openharmony/startup_init/pulls/2550
4.0.xhttps://gitee.com/openharmony/startup_init/pulls/2549
1
0
发布于2024.02.02
CVE漏洞描述漏洞影响CVSS3.1得分受影响的版本受影响的仓库修复链接
CVE-2023-49118软总线越界读漏洞本地攻击者通过本漏洞造成信息泄露2.9OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Releasecommunication_dsoftbus3.2.x
CVE-2023-43756软总线越界读漏洞本地攻击者通过本漏洞造成信息泄露2.9OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Releasecommunication_dsoftbus3.2.x
CVE-2023-45734软总线越界写漏洞近场攻击者通过本漏洞执行代码4.2OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Releasecommunication_dsoftbus3.2.x
CVE-2024-21860软总线释放后使用漏洞近场攻击者通过本漏洞在任意应用中执行代码8.2OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Releasecommunication_dsoftbus3.2.x 4.0.x
CVE-2024-21845软总线整数溢出漏洞近场攻击者通过本漏洞造成堆溢出2.9OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Releasecommunication_dsoftbus3.2.x 4.0.x
CVE-2024-21851软总线整数溢出漏洞近场攻击者通过本漏洞造成堆溢出2.9OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Releasecommunication_dsoftbus3.2.x 4.0.x
CVE-2024-21863软总线数据校验不完善的漏洞近场攻击者通过本漏洞造成DOS4.7OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Releasecommunication_dsoftbus3.2.x 4.0.x
CVE-2024-0285软总线未判断数据长度的漏洞近场攻击者通过本漏洞造成DOS4.7OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Releasecommunication_ipc3.2.x 4.0.x
以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本
CVECVSS 3.1 得分严重程度受影响的仓库受影响的OpenHarmony版本修复链接
CVE-2023-56785.3中危third_party_opensslOpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release3.2.x
CVE-2023-444298.8高危third_party_gstreamerOpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release3.2.x
CVE-2023-444468.8高危third_party_gstreamerOpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release3.2.x
CVE-2023-65108.8高危third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release3.2.x 4.0.x
CVE-2023-63459.6致命third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release3.2.x 4.0.x
CVE-2023-63478.8高危third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release3.2.x 4.0.x
CVE-2023-65088.8高危third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release3.2.x 4.0.x
CVE-2023-68177.8高危kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release3.2.x 4.0.x
CVE-2023-69317.8高危kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release3.2.x 4.0.x
CVE-2023-69327.0高危kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release3.2.x 4.0.x
CVE-2023-350017.8高危kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2023-71047.3高危third_party_sqliteOpenHarmony-v4.0-Release4.0.x
CVE-2023-67058.8高危third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release3.2.x 4.0.x
CVE-2023-67028.8高危third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release3.2.x 4.0.x
CVE-2023-67038.8高危third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-v3.2.4-Release OpenHarmony-v4.0-Release3.2.x 4.0.x
请在合入当月及之前全部已公开安全补丁之后,参考如下各维护版本的安全补丁标签更新方法,更新安全补丁标签至02月。
对应维护版本安全补丁修改方式参考链接
3.2.xhttps://gitee.com/openharmony/startup_init/pulls/2478
4.0.xhttps://gitee.com/openharmony/startup_init/pulls/2481
1
0
发布于2024.01.02
CVE漏洞描述漏洞影响CVSS3.1基础得分受影响的版本受影响的仓库修复链接
CVE-2023-47216Liteos-A 资源未释放的漏洞本地攻击者通过本漏洞造成DOS2.9OpenHarmony-v3.2-Release到OpenHarmony-v3.2.2third_party_musl3.2.x
CVE-2023-49142多媒体音频组件指针释放后使用的漏洞本地攻击者通过本漏洞造成音频组件崩溃4.0OpenHarmony-v3.2-Release到OpenHarmony-v3.2.2multimedia_audio_framework3.2.x
CVE-2023-47857多媒体相机组件指针释放后使用的漏洞本地攻击者通过本漏洞造成相机组件崩溃4.0OpenHarmony-v3.2-Release到OpenHarmony-v3.2.2multimedia_camera_framework3.2.x
CVE-2023-49135多媒体播放器组件指针释放后使用的漏洞本地攻击者通过本漏洞造成播放器组件崩溃4.0OpenHarmony-v3.2-Release到OpenHarmony-v3.2.2multimedia_player_framework3.2.x
CVE-2023-48360多媒体播放器组件指针释放后使用的漏洞本地攻击者通过本漏洞造成播放器组件崩溃4.0OpenHarmony-v3.2-Release到OpenHarmony-v3.2.2multimedia_player_framework3.2.x
以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本,详细信息请参考三方公告。
CVE严重程度CVSS 3.1得分受影响的仓库受影响的OpenHarmony版本修复链接
CVE-2023-58498.8高危third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-v3.2.2-Release OpenHarmony-v4.0-Release3.2.x 4.0.x
CVE-2023-54806.1中危third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-v3.2.2-Release OpenHarmony-v4.0-Release3.2.x 4.0.x
CVE-2023-54828.8高危third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-v3.2.2-Release OpenHarmony-v4.0-Release3.2.x 4.0.x
CVE-2023-59968.8高危third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-v3.2.2-Release OpenHarmony-v4.0-Release3.2.x 4.0.x
CVE-2023-61128.8高危third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-v3.2.2-Release OpenHarmony-v4.0-Release3.2.x 4.0.x
CVE-2023-59978.8高危third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-v3.2.2-Release OpenHarmony-v4.0-Release3.2.x 4.0.x
CVE-2023-57177.8高危kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2023-53637.5中危third_party_opensslOpenHarmony-v4.0-Release4.0.x
CVE-2022-469087.3中危third_party_sqliteOpenHarmony-v3.2-Release到OpenHarmony-v3.2.2-Release3.2.x
CVE-2023-404756.3中危third_party_gstreamerOpenHarmony-v3.2-Release到OpenHarmony-v3.2.2-Release OpenHarmony-v4.0-Release3.2.x 4.0.x
CVE-2023-404768.3高危third_party_gstreamerOpenHarmony-v3.2-Release到OpenHarmony-v3.2.2-Release OpenHarmony-v4.0-Release3.2.x 4.0.x
CVE-2023-54728.8高危third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-v3.2.2-Release OpenHarmony-v4.0-Release3.2.x 4.0.x
CVE-2023-54846.5中危third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-v3.2.2-Release OpenHarmony-v4.0-Release3.2.x 4.0.x
如下是各维护版本的安全补丁标签,请在合入当月及之前全部对应安全补丁之后,更新安全补丁标签。
安全补丁标签链接
2024年01月[4.0.x]
[3.2.x]
1
0
本次安全公告发布于2023.11.07
CVE漏洞描述漏洞影响CVSS3.1得分受影响的版本受影响的仓库修复链接
CVE-2023-4753内核中系统调用接收用户态参数函数使用错误可导致内核crash5.5 OpenHarmony-v3.2-Release到OpenHarmony-v3.2.2kernel_liteos_ahttps://gitee.com…
以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本
CVECVSS 3.1 得分严重程度受影响的仓库受影响的OpenHarmony版本修复链接
CVE-2023-427537.8高危kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3…
CVE-2023-21638.8高危kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.…
CVE-2023-48638.8高危third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-…
CVE-2023-49217.8高危kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.…
CVE-2023-48077.8高危third_party_opensslOpenHarmony-v3.2-Release到OpenHarmony-v…
CVE-2023-47638.8高危third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-…
CVE-2023-47628.8高危third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-…
CVE-2023-46227高危kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.2.…
CVE-2023-46237.8高危kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.…
CVE-2023-42067.8高危kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.…
CVE-2023-42077.8高危kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.…
CVE-2023-42087.8高危kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.…
CVE-2023-45728.8高危third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-…
CVE-2023-37777.8高危kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.…
请在合入当月及之前全部已公开安全补丁之后,参考如下各维护版本的安全补丁标签更新方法,更新安全补丁标签至11月。
对应维护版本安全补丁修改方式参考链接
3.2.xhttps://gitee.com/openharmony/startup_init/pulls/2330
1
0
本次批漏发布于2023.09.15
批漏信息禁运声明:下述issue将在2023年10月初在OpenHarmony社区安全公告,请注意对这些问题的保密,确保公开讨论在OpenHarmony社区公开公告之后。
备注:OpenHarmony 3.0-LTS和3.1-Release分支已停止维护,后续这两个分支的安全漏洞也不再维护,详情参见:
OpenHarmony 3.0-LTS和3.1-Release分支停止维护公告
以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本
CVECVSS 3.1 得分严重程度受影响的仓库受影响的OpenHarmony版本修复链接
CVE-2023-44595.5中危kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.…
CVE-2023-43877.1高危kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.…
CVE-2023-43855.5中危kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.…
CVE-2023-402837.8高危kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3…
CVE-2023-41945.5中危kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.…
CVE-2023-42736中危kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.2.…
CVE-2023-38127.8高危kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.…
CVE-2023-35677.1高危kernel_linux_5.10OpenHarmony-v3.2-Release到OpenHarmony-v3.…
CVE-2023-45728.8高危third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-…
CVE-2023-4427-1未知third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-v…
CVE-2023-43558.8高危third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-…
CVE-2023-43528.8高危third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-…
CVE-2023-43628.8高危third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-…
CVE-2023-43538.8高危third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-…
CVE-2023-43548.8高危third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-…
CVE-2023-43518.8高危third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-…
CVE-2023-43578.8高危third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-…
CVE-2023-40768.8高危third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-…
CVE-2023-40718.8高危third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-…
CVE-2023-40728.8高危third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-…
CVE-2022-49084.3中危third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-…
CVE-2022-4911-1未知third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-v…
CVE-2023-3598-1未知third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-v…
CVE-2022-49096.3中危third_party_chromiumOpenHarmony-v3.2-Release到OpenHarmony-…
请在合入当月及之前全部已公开安全补丁之后,参考如下各维护版本的安全补丁标签更新方法,更新安全补丁标签至10月。
对应维护版本安全补丁修改方式参考链接
3.2.xhttps://gitee.com/openharmony/startup_init/pulls/2244
1
0

OpenHarmony2023年06月安全公告 Security Vulnerabilities in June 2023
by Zhangadong (zhangadong, OS) 09 Jun '23
by Zhangadong (zhangadong, OS) 09 Jun '23
09 Jun '23
2023年06月安全漏洞
发布于2023.06.02
最后更新于2023.06.02
以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本,详细信息请参考三方公告。
CVE
严重程度
CVSS 3.1得分
受影响的OpenHarmony版本
修复链接
CVE-2023-27533
高
8.8
OpenHarmony-v3.2-Release
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0到OpenHarmony-v3.0.8
3.2.x<https://gitee.com/openharmony/third_party_libxml2/pulls/44>
3.1.x<https://gitee.com/openharmony/third_party_curl/pulls/130>
3.0.x<https://gitee.com/openharmony/third_party_curl/pulls/131>
CVE-2023-27534
高
8.8
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0到OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/third_party_curl/pulls/130>
3.0.x<https://gitee.com/openharmony/third_party_curl/pulls/131>
CVE-2023-27535
高
7.5
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0到OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/third_party_curl/pulls/130>
3.0.x<https://gitee.com/openharmony/third_party_curl/pulls/131>
CVE-2023-27536
严重
9.8
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0到OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/third_party_curl/pulls/130>
3.0.x<https://gitee.com/openharmony/third_party_curl/pulls/131>
CVE-2023-27538
中
5.5
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0到OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/third_party_curl/pulls/130>
3.0.x<https://gitee.com/openharmony/third_party_curl/pulls/131>
CVE-2023-29469
中
5.9
OpenHarmony-v3.2-Release
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0到OpenHarmony-v3.0.8
3.2.x<https://gitee.com/openharmony/third_party_libxml2/pulls/44>
3.1.x<https://gitee.com/openharmony/third_party_libxml2/pulls/45>
3.0.x<https://gitee.com/openharmony/third_party_libxml2/pulls/46>
CVE-2023-28484
中
5.9
OpenHarmony-v3.2-Release
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0到OpenHarmony-v3.0.8
3.2.x<https://gitee.com/openharmony/third_party_libxml2/pulls/44>
3.1.x<https://gitee.com/openharmony/third_party_libxml2/pulls/45>
3.0.x<https://gitee.com/openharmony/third_party_libxml2/pulls/46>
如下是各维护版本的安全补丁标签,请在合入对应安全补丁的同时,更新安全补丁标签。
安全补丁标签
链接
2023年6月
[3.2.x]<https://gitee.com/openharmony/startup_init/pulls/2020>
[3.1.x]<https://gitee.com/openharmony/startup_syspara_lite/pulls/239>
[3.1.x]<https://gitee.com/openharmony/startup_init/pulls/2007>
[3.0.x]<https://gitee.com/openharmony/startup_syspara_lite/pulls/238>
Security Vulnerabilities in June 2023
published June 2,2023
updated June 2,2023
The following table lists the third-party library vulnerabilities with only the CVE, severity, and affected OpenHarmony versions provided. For more details, see the security bulletins released by third-parties.
CVE
severity
CVSS 3.1
affected OpenHarmony versions
fix links
CVE-2023-27533
High
8.8
OpenHarmony-v3.2-Release
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0 through OpenHarmony-v3.0.8
3.2.x<https://gitee.com/openharmony/third_party_curl/pulls/128>
3.1.x<https://gitee.com/openharmony/third_party_curl/pulls/130>
3.0.x<https://gitee.com/openharmony/third_party_curl/pulls/131>
CVE-2023-27534
High
8.8
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0 through OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/third_party_curl/pulls/130>
3.0.x<https://gitee.com/openharmony/third_party_curl/pulls/131>
CVE-2023-27535
High
7.5
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0 through OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/third_party_curl/pulls/130>
3.0.x<https://gitee.com/openharmony/third_party_curl/pulls/131>
CVE-2023-27536
Critical
9.8
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0 through OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/third_party_curl/pulls/130>
3.0.x<https://gitee.com/openharmony/third_party_curl/pulls/131>
CVE-2023-27538
Medium
5.5
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0 through OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/third_party_curl/pulls/130>
3.0.x<https://gitee.com/openharmony/third_party_curl/pulls/131>
CVE-2023-29469
Medium
5.9
OpenHarmony-v3.2-Release
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0 through OpenHarmony-v3.0.8
3.2.x<https://gitee.com/openharmony/third_party_libxml2/pulls/44>
3.1.x<https://gitee.com/openharmony/third_party_libxml2/pulls/45>
3.0.x<https://gitee.com/openharmony/third_party_libxml2/pulls/46>
CVE-2023-28484
Medium
5.9
OpenHarmony-v3.2-Release
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0 through OpenHarmony-v3.0.8
3.2.x<https://gitee.com/openharmony/third_party_libxml2/pulls/44>
3.1.x<https://gitee.com/openharmony/third_party_libxml2/pulls/45>
3.0.x<https://gitee.com/openharmony/third_party_libxml2/pulls/46>
The following are the security patch labels for each maintenance version. Please update the security patch labels while incorporating the corresponding security patches.
Security patch label
fix links
June 2023
[3.2.x]<https://gitee.com/openharmony/startup_init/pulls/2020>
[3.1.x]<https://gitee.com/openharmony/startup_syspara_lite/pulls/239>
[3.1.x]<https://gitee.com/openharmony/startup_init/pulls/2007>
[3.0.x]<https://gitee.com/openharmony/startup_syspara_lite/pulls/238>
1
0

撤回: OpenHarmony2023年06月安全公告 Security Vulnerabilities in June 2023
by Zhangadong (zhangadong, OS) 09 Jun '23
by Zhangadong (zhangadong, OS) 09 Jun '23
09 Jun '23
Zhangadong (zhangadong, OS) 将撤回邮件“OpenHarmony2023年06月安全公告 Security Vulnerabilities in June 2023”。
1
0

撤回: OpenHarmony2023年06月安全公告 Security Vulnerabilities in June 2023
by Zhangadong (zhangadong, OS) 09 Jun '23
by Zhangadong (zhangadong, OS) 09 Jun '23
09 Jun '23
Zhangadong (zhangadong, OS) 将撤回邮件“OpenHarmony2023年06月安全公告 Security Vulnerabilities in June 2023”。
1
0

撤回: OpenHarmony2023年06月安全公告 Security Vulnerabilities in June 2023
by Zhangadong (zhangadong, OS) 09 Jun '23
by Zhangadong (zhangadong, OS) 09 Jun '23
09 Jun '23
Zhangadong (zhangadong, OS) 将撤回邮件“OpenHarmony2023年06月安全公告 Security Vulnerabilities in June 2023”。
1
0

10 May '23
2023年05月安全漏洞
发布于2023.05.09
最后更新于2023.05.09
以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本,详细信息请参考三方公告。
CVE
严重程度
CVSS 3.1得分
受影响的仓库
受影响的OpenHarmony版本
修复链接
CVE-2021-36647
中
4.7
third_party_mbedtls
device_hisilicon_hispark_taurus
OpenHarmony-v3.0到OpenHarmony-v3.0.8
3.0.x<https://gitee.com/openharmony/third_party_mbedtls/pulls/86>
3.0.x<https://gitee.com/openharmony/device_hisilicon_hispark_taurus/pulls/129>
CVE-2023-1382
中
5.5
kernel_linux_5.10
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0到OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/804>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/805>
CVE-2023-0386
中
5.3
kernel_linux_4.19
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0到OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/119>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/120>
CVE-2023-1281
高
7.8
kernel_linux_5.10
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0到OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/802>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/803>
CVE-2023-28772
高
7.8
kernel_linux_4.19
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0到OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/119>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/120>
CVE-2023-1637
低
3.3
kernel_linux_4.19
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0到OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/119>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/120>
CVE-2021-3923
低
3.3
kernel_linux_4.19
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0到OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/119>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/120>
CVE-2023-1380
高
7.1
kernel_linux_5.10
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0到OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/802>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/803>
CVE-2023-1582
中
4.7
kernel_linux_5.10
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0到OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/765>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/766>
CVE-2022-48434
高
8.1
third_party_ffmpeg
OpenHarmony-v3.2-Release
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0到OpenHarmony-v3.0.8
3.2.x<https://gitee.com/openharmony/third_party_ffmpeg/pulls/81>
3.1.x<https://gitee.com/openharmony/third_party_ffmpeg/pulls/82>
3.0.x<https://gitee.com/openharmony/third_party_ffmpeg/pulls/83>
CVE-2023-1838
中
5.3
kernel_linux_5.10
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0到OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/773>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/774>
CVE-2023-1838
中
5.3
kernel_linux_4.19
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0到OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/124>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/125>
CVE-2023-1855
中
6.3
kernel_linux_5.10
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0到OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/802>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/803>
CVE-2023-30456
高
7.8
kernel_linux_5.10
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0到OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/802>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/803>
CVE-2022-45934
高
7.8
kernel_linux_4.19
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0到OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/129>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/130>
CVE-2022-2978
高
7.8
kernel_linux_4.19
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0到OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/121>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/122>
CVE-2022-29581
高
7.8
kernel_linux_4.19
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0到OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/124>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/125>
CVE-2023-1989
高
7.0
kernel_linux_5.10
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0到OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/802>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/803>
CVE-2023-1829
高
7.8
kernel_linux_5.10
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0到OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/802>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/803>
CVE-2023-1990
中
4.8
kernel_linux_5.10
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0到OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/802>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/803>
CVE-2023-1859
中
6.4
kernel_linux_5.10
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0到OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/802>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/803>
CVE-2023-2004
中
5.3
third_party_freetype
OpenHarmony-v3.2-Release
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0到OpenHarmony-v3.0.8
3.2.x<https://gitee.com/openharmony/third_party_freetype/pulls/51>
3.1.x<https://gitee.com/openharmony/third_party_freetype/pulls/52>
3.0.x<https://gitee.com/openharmony/third_party_freetype/pulls/53>
CVE-2023-2006
高
7.8
kernel_linux_5.10
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0到OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/811>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/812>
CVE-2023-2008
高
7.8
kernel_linux_5.10
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0到OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/787>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/788>
Security Vulnerabilities in May 2023
published May 9,2023
updated May 9,2023
The following table lists the third-party library vulnerabilities with only the CVE, severity, and affected OpenHarmony versions provided. For more details, see the security bulletins released by third-parties.
CVE
severity
CVSS3.1
affected repository
affected OpenHarmony versions
fix link
CVE-2021-36647
Medium
4.7
third_party_mbedtls
device_hisilicon_hispark_taurus
OpenHarmony-v3.0 through OpenHarmony-v3.0.8
3.0.x<https://gitee.com/openharmony/third_party_mbedtls/pulls/86>
3.0.x<https://gitee.com/openharmony/device_hisilicon_hispark_taurus/pulls/129>
CVE-2023-1382
Medium
5.5
kernel_linux_5.10
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0 through OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/804>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/805>
CVE-2023-0386
Medium
5.3
kernel_linux_4.19
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0 through OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/119>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/120>
CVE-2023-1281
High
7.8
kernel_linux_5.10
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0 through OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/802>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/803>
CVE-2023-28772
High
7.8
kernel_linux_4.19
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0 through OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/119>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/120>
CVE-2023-1637
Low
3.3
kernel_linux_4.19
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0 through OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/119>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/120>
CVE-2021-3923
Low
3.3
kernel_linux_4.19
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0 through OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/119>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/120>
CVE-2023-1380
High
7.1
kernel_linux_5.10
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0 through OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/802>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/803>
CVE-2023-1582
Medium
4.7
kernel_linux_5.10
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0 through OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/765>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/766>
CVE-2022-48434
High
8.1
third_party_ffmpeg
OpenHarmony-v3.2-Release
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0 through OpenHarmony-v3.0.8
3.2.x<https://gitee.com/openharmony/third_party_ffmpeg/pulls/81>
3.1.x<https://gitee.com/openharmony/third_party_ffmpeg/pulls/82>
3.0.x<https://gitee.com/openharmony/third_party_ffmpeg/pulls/83>
CVE-2023-1838
Medium
5.3
kernel_linux_5.10
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0 through OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/773>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/774>
CVE-2023-1838
Medium
5.3
kernel_linux_4.19
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0 through OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/124>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/125>
CVE-2023-1855
Medium
6.3
kernel_linux_5.10
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0 through OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/802>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/803>
CVE-2023-30456
High
7.8
kernel_linux_5.10
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0 through OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/802>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/803>
CVE-2022-45934
High
7.8
kernel_linux_4.19
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0 through OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/129>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/130>
CVE-2022-2978
High
7.8
kernel_linux_4.19
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0 through OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/121>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/122>
CVE-2022-29581
High
7.8
kernel_linux_4.19
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0 through OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/124>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/125>
CVE-2023-1989
High
7.0
kernel_linux_5.10
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0 through OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/802>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/803>
CVE-2023-1829
High
7.8
kernel_linux_5.10
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0 through OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/802>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/803>
CVE-2023-1990
Medium
4.8
kernel_linux_5.10
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0 through OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/802>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/803>
CVE-2023-1859
Medium
6.4
kernel_linux_5.10
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0 through OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/802>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/803>
CVE-2023-2004
Medium
5.3
third_party_freetype
OpenHarmony-v3.2-Release
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0 through OpenHarmony-v3.0.8
3.2.x<https://gitee.com/openharmony/third_party_freetype/pulls/51>
3.1.x<https://gitee.com/openharmony/third_party_freetype/pulls/52>
3.0.x<https://gitee.com/openharmony/third_party_freetype/pulls/53>
CVE-2023-2006
High
7.8
kernel_linux_5.10
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0 through OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/811>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/812>
CVE-2023-2008
High
7.8
kernel_linux_5.10
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0 through OpenHarmony-v3.0.8
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/787>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/788>
1
0

04 Apr '23
2023年04月安全漏洞
发布于2023.04.04
最后更新于2023.04.04
以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本,详细信息请参考三方公告。
CVE
严重程度
CVSS3.1
受影响的OpenHarmony版本
修复链接
CVE-2023-0597
中
5.5
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/705>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/706>
CVE-2022-30787
中
6.7
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1
3.1.x<https://gitee.com/openharmony/third_party_ntfs-3g/pulls/18>
CVE-2015-20107
高
7.6
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
3.1.x<https://gitee.com/openharmony/third_party_python/pulls/45>
CVE-2022-33068
中
5.5
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
OpenHarmony-v1.1.1-LTS到OpenHarmony-v1.1.5-LTS
3.1.x<https://gitee.com/openharmony/third_party_harfbuzz/pulls/47>
3.0.x<https://gitee.com/openharmony/third_party_harfbuzz/pulls/48>
1.1.x<https://gitee.com/openharmony/third_party_harfbuzz/pulls/49>
CVE-2022-4904
中
5.5
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/third_party_cares/pulls/12>
3.0.x<https://gitee.com/openharmony/third_party_cares/pulls/11>
CVE-2022-3594
中
5.3
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/100>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/101>
CVE-2023-22995
中
5.5
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/725>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/726>
CVE-2023-22999
中
5.0
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/733>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/734>
CVE-2023-26545
中
6.5
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/725>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/726>
CVE-2022-47929
中
5.5
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/103>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/104>
CVE-2022-2873
中
5.5
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/103>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/104>
CVE-2023-23559
高
7.8
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/103>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/104>
CVE-2023-1118
中
5.3
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/725>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/726>
CVE-2023-1118
中
5.3
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/107>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/108>
CVE-2022-1652
高
7.8
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/107>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/108>
CVE-2021-3760
高
7.8
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/107>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/108>
CVE-2021-37576
高
7.8
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/106>
CVE-2023-0461
高
7.8
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/725>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/726>
CVE-2023-0461
高
7.8
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/107>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/108>
CVE-2023-23455
中
5.5
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/103>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/104>
CVE-2023-26545
高
7.8
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/107>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/108>
CVE-2022-0480
中
5.5
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/107>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/108>
CVE-2023-1076
中
4.7
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/725>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/726>
CVE-2023-1073
中
6.3
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/736>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/738>
CVE-2023-1074
中
4.7
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/736>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/738>
CVE-2023-1078
高
7.8
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/725>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/726>
CVE-2023-1095
中
5.5
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/708>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/709>
CVE-2023-23000
中
5.3
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/725>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/726>
CVE-2023-23002
中
5.3
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/711>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/712>
CVE-2023-23004
中
5.5
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/725>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/726>
CVE-2023-23006
高
8.4
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/713>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/714>
CVE-2023-26607
中
5.2
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/745>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/746>
CVE-2023-0030
高
7.8
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/111>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/112>
CVE-2023-23000
中
5.3
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/117>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/118>
CVE-2023-1252
高
7.0
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/723>
CVE-2023-1390
高
7.5
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/114>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/115>
CVE-2023-1078
中
5.3
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/114>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/115>
CVE-2023-1074
中
4.7
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/114>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/115>
CVE-2023-28328
中
5.5
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/745>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/746>
CVE-2023-0464
中
5.0
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/third_party_openssl/pulls/95>
3.0.x<https://gitee.com/openharmony/third_party_openssl/pulls/96>
CVE-2023-1637
低
3.3
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/758>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/759>
CVE-2023-0465
中
5.6
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/third_party_openssl/pulls/99>
3.0.x<https://gitee.com/openharmony/third_party_openssl/pulls/100>
CVE-2023-0466
中
5.6
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/third_party_openssl/pulls/99>
3.0.x<https://gitee.com/openharmony/third_party_openssl/pulls/100>
Security Vulnerabilities in April 2023
published April 4,2023
updated April 4,2023
The following table lists the third-party library vulnerabilities with only the CVE, severity, and affected OpenHarmony versions provided. For more details, see the security bulletins released by third-parties.
CVE
severity
CVSS3.1
affected OpenHarmony versions
fix link
CVE-2023-0597
Medium
5.5
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/705>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/706>
CVE-2022-30787
Medium
6.7
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1
3.1.x<https://gitee.com/openharmony/third_party_ntfs-3g/pulls/18>
CVE-2015-20107
High
7.6
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
3.1.x<https://gitee.com/openharmony/third_party_python/pulls/45>
CVE-2022-33068
Medium
5.5
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
OpenHarmony-v1.1.1-LTS through OpenHarmony-v1.1.5-LTS
3.1.x<https://gitee.com/openharmony/third_party_harfbuzz/pulls/47>
3.0.x<https://gitee.com/openharmony/third_party_harfbuzz/pulls/48>
1.1.x<https://gitee.com/openharmony/third_party_harfbuzz/pulls/49>
CVE-2022-4904
Medium
5.5
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/third_party_cares/pulls/12>
3.0.x<https://gitee.com/openharmony/third_party_cares/pulls/11>
CVE-2022-3594
Medium
5.3
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/100>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/101>
CVE-2023-22995
Medium
5.5
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/725>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/726>
CVE-2023-22999
Medium
5.0
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/733>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/734>
CVE-2023-26545
Medium
6.5
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/725>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/726>
CVE-2022-47929
Medium
5.5
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/103>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/104>
CVE-2022-2873
Medium
5.5
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/103>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/104>
CVE-2023-23559
High
7.8
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/103>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/104>
CVE-2023-1118
Medium
5.3
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/725>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/726>
CVE-2023-1118
Medium
5.3
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/107>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/108>
CVE-2022-1652
High
7.8
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/107>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/108>
CVE-2021-3760
High
7.8
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/107>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/108>
CVE-2021-37576
High
7.8
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/106>
CVE-2023-0461
High
7.8
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/725>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/726>
CVE-2023-0461
High
7.8
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/107>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/108>
CVE-2023-23455
Medium
5.5
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/103>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/104>
CVE-2023-26545
High
7.8
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/107>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/108>
CVE-2022-0480
Medium
5.5
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/107>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/108>
CVE-2023-1076
Medium
4.7
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/725>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/726>
CVE-2023-1073
Medium
6.3
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/736>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/738>
CVE-2023-1074
Medium
4.7
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/736>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/738>
CVE-2023-1078
High
7.8
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/725>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/726>
CVE-2023-1095
Medium
5.5
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/708>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/709>
CVE-2023-23000
Medium
5.3
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/725>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/726>
CVE-2023-23002
Medium
5.3
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/711>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/712>
CVE-2023-23004
Medium
5.5
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/725>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/726>
CVE-2023-23006
High
8.4
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/713>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/714>
CVE-2023-26607
Medium
5.2
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/745>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/746>
CVE-2023-0030
High
7.8
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/111>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/112>
CVE-2023-23000
Medium
5.3
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/117>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/118>
CVE-2023-1252
High
7.0
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/723>
CVE-2023-1390
High
7.5
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/114>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/115>
CVE-2023-1078
Medium
5.3
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/114>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/115>
CVE-2023-1074
Medium
4.7
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/114>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/115>
CVE-2023-28328
Medium
5.5
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/745>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/746>
CVE-2023-0464
Medium
5.0
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/third_party_openssl/pulls/95>
3.0.x<https://gitee.com/openharmony/third_party_openssl/pulls/96>
CVE-2023-1637
Low
3.3
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/758>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/759>
CVE-2023-0465
Medium
5.6
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/third_party_openssl/pulls/99>
3.0.x<https://gitee.com/openharmony/third_party_openssl/pulls/100>
CVE-2023-0466
Medium
5.6
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/third_party_openssl/pulls/99>
3.0.x<https://gitee.com/openharmony/third_party_openssl/pulls/100>
1
0

07 Mar '23
2023年03月安全漏洞
发布于2023.03.07
最后更新于2023.03.07
漏洞编号
相关漏洞
漏洞描述
漏洞影响
CVSS3.1基础得分
受影响的版本
受影响的仓库
修复链接
参考链接
OpenHarmony-SA-2023-0301
CVE-2023-24465
WLAN组件子系统通信设备服务的一个接口,在接受外部数据时存在空指针引用。
本地攻击者利用此漏洞,可导致当前应用crash。
5.5
OpenHarmony-v3.1-Release 到 OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS 到 OpenHarmony-v3.0.7-LTS
communication_wifi
3.1.x<https://gitee.com/openharmony/communication_wifi/pulls/788>
3.0.x<https://gitee.com/openharmony/communication_wifi/pulls/862>
本项目组上报
OpenHarmony-SA-2023-0302
CVE-2023-25947
包管理模块存在安装hap包时没有做有效性判断的漏洞。
本地攻击者利用此漏洞构造非法数据,在安装hap包时可以导致系统无响应。
6.2
OpenHarmony-v3.1-Release 到 OpenHarmony-v3.1.4-Release
bundlemanager_bundle_framework
3.1.x<https://gitee.com/openharmony/bundlemanager_bundle_framework/pulls/3094>
本项目组上报
以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本,详细信息请参考三方公告。
CVE
严重程度
受影响的OpenHarmony版本
修复链接
CVE-2022-47946
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.5-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/646>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/647>
CVE-2022-2196
低
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/665>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/666>
CVE-2023-0047
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.5-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/631>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/632>
CVE-2023-23559
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/661>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/662>
CVE-2022-3640
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.5-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/659>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/660>
CVE-2022-47929
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/677>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/678>
CVE-2023-0179
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/661>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/662>
CVE-2023-0394
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/677>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/678>
CVE-2023-23454
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/661>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/662>
CVE-2023-23455
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/661>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/662>
CVE-2023-0590
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/687>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/688>
CVE-2023-0615
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/696>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/697>
CVE-2023-0045
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/696>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/697>
CVE-2023-20938
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/696>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/697>
CVE-2022-3176
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/553>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/561>
CVE-2023-0045
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/96>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/97>
CVE-2022-3028
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/98>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/99>
CVE-2020-36516
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/682>
CVE-2022-3341
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.5-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
OpenHarmony-v1.0.1-release到OpenHarmony-v1.1.5-LTS
3.1.x<https://gitee.com/openharmony/third_party_ffmpeg/pulls/74>
3.0.x<https://gitee.com/openharmony/third_party_ffmpeg/pulls/73>
1.1.x<https://gitee.com/openharmony/device_hisilicon_third_party_ffmpeg/pulls/19>
CVE-2022-4450
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
OpenHarmony-v1.0.1-release到OpenHarmony-v1.1.5-LTS
3.1.x<https://gitee.com/openharmony/third_party_openssl/pulls/80>
3.0.x<https://gitee.com/openharmony/third_party_openssl/pulls/81>
1.1.x<https://gitee.com/openharmony/third_party_openssl/pulls/82>
CVE-2023-0286
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
OpenHarmony-v1.0.1-release到OpenHarmony-v1.1.5-LTS
3.1.x<https://gitee.com/openharmony/third_party_openssl/pulls/83>
3.0.x<https://gitee.com/openharmony/third_party_openssl/pulls/85>
1.1.x<https://gitee.com/openharmony/third_party_openssl/pulls/86>
CVE-2023-0215
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
OpenHarmony-v1.0.1-release到OpenHarmony-v1.1.5-LTS
3.1.x<https://gitee.com/openharmony/third_party_openssl/pulls/83>
3.0.x<https://gitee.com/openharmony/third_party_openssl/pulls/85>
1.1.x<https://gitee.com/openharmony/third_party_openssl/pulls/86>
CVE-2022-4304
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
OpenHarmony-v1.0.1-release到OpenHarmony-v1.1.5-LTS
3.1.x<https://gitee.com/openharmony/third_party_openssl/pulls/87>
3.0.x<https://gitee.com/openharmony/third_party_openssl/pulls/88>
1.1.x<https://gitee.com/openharmony/third_party_openssl/pulls/89>
CVE-2021-41751
严重
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/third_party_jerryscript/pulls/101>
3.0.x<https://gitee.com/openharmony/third_party_jerryscript/pulls/102>
CVE-2021-43453
严重
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/third_party_jerryscript/pulls/103>
3.0.x<https://gitee.com/openharmony/third_party_jerryscript/pulls/104>
CVE-2022-1304
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/third_party_e2fsprogs/pulls/51>
3.0.x<https://gitee.com/openharmony/third_party_e2fsprogs/pulls/52>
CVE-2023-23914
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
OpenHarmony-v1.0.1-release到OpenHarmony-v1.1.5-LTS
3.1.x<https://gitee.com/openharmony/third_party_curl/pulls/110>
3.0.x<https://gitee.com/openharmony/third_party_curl/pulls/111>
1.1.x<https://gitee.com/openharmony/third_party_curl/pulls/112>
CVE-2023-23915
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
OpenHarmony-v1.0.1-release到OpenHarmony-v1.1.5-LTS
3.1.x<https://gitee.com/openharmony/third_party_curl/pulls/110>
3.0.x<https://gitee.com/openharmony/third_party_curl/pulls/111>
1.1.x<https://gitee.com/openharmony/third_party_curl/pulls/112>
CVE-2023-23916
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
OpenHarmony-v1.0.1-release到OpenHarmony-v1.1.5-LTS
3.1.x<https://gitee.com/openharmony/third_party_curl/pulls/110>
3.0.x<https://gitee.com/openharmony/third_party_curl/pulls/111>
1.1.x<https://gitee.com/openharmony/third_party_curl/pulls/112>
CVE-2020-35538
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/third_party_flutter/pulls/250>
3.0.x<https://gitee.com/openharmony/third_party_flutter/pulls/251>
CVE-2022-37434
严重
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/third_party_flutter/pulls/247>
3.0.x<https://gitee.com/openharmony/third_party_flutter/pulls/248>
Security Vulnerabilities in Feburary 2023
published March 7,2023
updated March 7,2023
Vulnerability ID
related Vulnerability
Vulnerability Description
Vulnerability Impact
CVSS3.1 Base Score
affected versions
affected projects
fix link
reference
OpenHarmony-SA-2023-0301
CVE-2023-24465
Communication Wi-Fi subsystem has a null pointer reference vulnerability when receiving external data.
Local attackers can exploit this vulnerability to cause the current application to crash.
5.5
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
communication_wifi
3.1.x<https://gitee.com/openharmony/communication_wifi/pulls/788>
3.0.x<https://gitee.com/openharmony/communication_wifi/pulls/862>
Reported by OpenHarmony Team
OpenHarmony-SA-2023-0302
CVE-2023-25947
The bundle management subsystem has a improper input validation when installing a HAP package.
Local attackers can exploit this vulnerability to cause a DoS attack to the system when installing a malicious HAP package.
6.2
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
bundlemanager_bundle_framework
3.1.x<https://gitee.com/openharmony/bundlemanager_bundle_framework/pulls/3094>
Reported by OpenHarmony Team
The following table lists the third-party library vulnerabilities with only the CVE, severity, and affected OpenHarmony versions provided. For more details, see the security bulletins released by third-parties.
CVE
severity
affected OpenHarmony versions
fix link
CVE-2022-47946
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.5-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/646>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/647>
CVE-2022-2196
Low
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/665>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/666>
CVE-2023-0047
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.5-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/631>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/632>
CVE-2023-23559
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/661>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/662>
CVE-2022-3640
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.5-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/659>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/660>
CVE-2022-47929
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/677>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/678>
CVE-2023-0179
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/661>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/662>
CVE-2023-0394
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/677>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/678>
CVE-2023-23454
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/661>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/662>
CVE-2023-23455
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/661>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/662>
CVE-2023-0590
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/687>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/688>
CVE-2023-0615
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/696>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/697>
CVE-2023-0045
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/696>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/697>
CVE-2023-20938
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/696>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/697>
CVE-2022-3176
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/553>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/561>
CVE-2023-0045
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/96>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/97>
CVE-2022-3028
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/98>
3.0.x<https://gitee.com/openharmony/kernel_linux_4.19/pulls/99>
CVE-2020-36516
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/682>
CVE-2022-3341
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.5-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
OpenHarmony-v1.0.1-release through OpenHarmony-v1.1.5-LTS
3.1.x<https://gitee.com/openharmony/third_party_ffmpeg/pulls/74>
3.0.x<https://gitee.com/openharmony/third_party_ffmpeg/pulls/73>
1.1.x<https://gitee.com/openharmony/device_hisilicon_third_party_ffmpeg/pulls/19>
CVE-2022-4450
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
OpenHarmony-v1.0.1-release through OpenHarmony-v1.1.5-LTS
3.1.x<https://gitee.com/openharmony/third_party_openssl/pulls/80>
3.0.x<https://gitee.com/openharmony/third_party_openssl/pulls/81>
1.1.x<https://gitee.com/openharmony/third_party_openssl/pulls/82>
CVE-2023-0286
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
OpenHarmony-v1.0.1-release through OpenHarmony-v1.1.5-LTS
3.1.x<https://gitee.com/openharmony/third_party_openssl/pulls/83>
3.0.x<https://gitee.com/openharmony/third_party_openssl/pulls/85>
1.1.x<https://gitee.com/openharmony/third_party_openssl/pulls/86>
CVE-2023-0215
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
OpenHarmony-v1.0.1-release through OpenHarmony-v1.1.5-LTS
3.1.x<https://gitee.com/openharmony/third_party_openssl/pulls/83>
3.0.x<https://gitee.com/openharmony/third_party_openssl/pulls/85>
1.1.x<https://gitee.com/openharmony/third_party_openssl/pulls/86>
CVE-2022-4304
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
OpenHarmony-v1.0.1-release through OpenHarmony-v1.1.5-LTS
3.1.x<https://gitee.com/openharmony/third_party_openssl/pulls/87>
3.0.x<https://gitee.com/openharmony/third_party_openssl/pulls/88>
1.1.x<https://gitee.com/openharmony/third_party_openssl/pulls/89>
CVE-2021-41751
Critical
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/third_party_jerryscript/pulls/101>
3.0.x<https://gitee.com/openharmony/third_party_jerryscript/pulls/102>
CVE-2021-43453
Critical
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/third_party_jerryscript/pulls/103>
3.0.x<https://gitee.com/openharmony/third_party_jerryscript/pulls/104>
CVE-2022-1304
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/third_party_e2fsprogs/pulls/51>
3.0.x<https://gitee.com/openharmony/third_party_e2fsprogs/pulls/52>
CVE-2023-23914
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
OpenHarmony-v1.0.1-release through OpenHarmony-v1.1.5-LTS
3.1.x<https://gitee.com/openharmony/third_party_curl/pulls/110>
3.0.x<https://gitee.com/openharmony/third_party_curl/pulls/111>
1.1.x<https://gitee.com/openharmony/third_party_curl/pulls/112>
CVE-2023-23915
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
OpenHarmony-v1.0.1-release through OpenHarmony-v1.1.5-LTS
3.1.x<https://gitee.com/openharmony/third_party_curl/pulls/110>
3.0.x<https://gitee.com/openharmony/third_party_curl/pulls/111>
1.1.x<https://gitee.com/openharmony/third_party_curl/pulls/112>
CVE-2023-23916
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
OpenHarmony-v1.0.1-release through OpenHarmony-v1.1.5-LTS
3.1.x<https://gitee.com/openharmony/third_party_curl/pulls/110>
3.0.x<https://gitee.com/openharmony/third_party_curl/pulls/111>
1.1.x<https://gitee.com/openharmony/third_party_curl/pulls/112>
CVE-2020-35538
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/third_party_flutter/pulls/250>
3.0.x<https://gitee.com/openharmony/third_party_flutter/pulls/251>
CVE-2022-37434
Critical
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
3.1.x<https://gitee.com/openharmony/third_party_flutter/pulls/247>
3.0.x<https://gitee.com/openharmony/third_party_flutter/pulls/248>
1
0

07 Feb '23
2023年02月安全漏洞
发布于2022.02.07
最后更新于2022.02.07
漏洞编号
相关漏洞
漏洞描述
漏洞影响
CVSS3.1基础得分
受影响的版本
受影响的仓库
修复链接
参考链接
OpenHarmony-SA-2023-0201
CVE-2023-0083
ArkUI框架子系统未对入参进行类型检查导致类型混淆,造成访问非法内存。
攻击者可在本地内发起攻击,造成当前应用崩溃。
4.0
OpenHarmony-v3.1-Release 到 OpenHarmony-v3.1.5-Release
OpenHarmony-v3.0-LTS 到 OpenHarmony-v3.0.7-LTS
arkui_ace_engine
3.1.x<https://gitee.com/openharmony/arkui_ace_engine/pulls/8872>
3.0.x<https://gitee.com/openharmony/arkui_ace_engine/pulls/8877>
研究员上报
OpenHarmony-SA-2023-0202
CVE-2023-22301
内核子系统中hmdfs存在内核任意内存越界读漏洞。
攻击者可发起远程攻击,可获取目标系统的内核内存数据。
6.5
OpenHarmony-v3.1-Release 到 OpenHarmony-v3.1.5-Release
kernel_linux_5.10
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/656>
研究员上报
OpenHarmony-SA-2023-0203
CVE-2023-22436
内核子系统中check_permission_for_set_tokenid函数中存在UAF漏洞。
本地攻击者利用该漏洞攻击可以权限提升,获得root权限。
7.8
OpenHarmony-v3.1-Release 到 OpenHarmony-v3.1.5-Release
kernel_linux_5.10
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/598>
研究员上报
以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本,详细信息请参考三方公告。
CVE
严重程度
受影响的OpenHarmony版本
修复链接
CVE-2022-2347
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/third_party_u-boot/pulls/62>
3.0.x<https://gitee.com/openharmony/third_party_u-boot/pulls/63>
CVE-2022-4135
严重
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.5-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/546>
CVE-2022-4186
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.5-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/546>
CVE-2022-4438
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.5-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/546>
CVE-2022-4437
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.5-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/546>
CVE-2022-4436
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.5-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/546>
CVE-2022-41218
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/646>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/647>
CVE-2022-3424
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.5-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/646>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/647>
CVE-2022-4129
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/586>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/587>
CVE-2022-42328
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.5-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/646>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/647>
CVE-2022-3643
严重
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.5-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/646>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/647>
CVE-2022-3105
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/579>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/580>
CVE-2022-3104
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/579>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/580>
CVE-2022-3115
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/579>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/580>
CVE-2022-3113
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/579>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/580>
CVE-2022-3112
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/579>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/580>
CVE-2022-3111
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/584>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/585>
CVE-2022-3108
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/586>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/587>
CVE-2022-3107
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/590>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/591>
CVE-2022-3106
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/592>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/593>
CVE-2022-47519
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/586>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/587>
CVE-2022-43551
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.5-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
OpenHarmony-v1.1.0-Release到OpenHarmony-v1.1.5-LTS
3.1.x<https://gitee.com/openharmony/third_party_curl/pulls/99>
3.0.x<https://gitee.com/openharmony/third_party_curl/pulls/100>
1.1.x<https://gitee.com/openharmony/third_party_curl/pulls/101>
CVE-2022-43552
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.5-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
OpenHarmony-v1.1.0-Release到OpenHarmony-v1.1.5-LTS
3.1.x<https://gitee.com/openharmony/third_party_curl/pulls/99>
3.0.x<https://gitee.com/openharmony/third_party_curl/pulls/100>
1.1.x<https://gitee.com/openharmony/third_party_curl/pulls/101>
CVE-2022-47518
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/586>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/587>
CVE-2022-47520
低
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/586>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/587>
CVE-2022-47521
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/586>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/587>
CVE-2022-3109
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.5-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
OpenHarmony-v1.1.0-Release到OpenHarmony-v1.1.5-LTS
3.1.x<https://gitee.com/openharmony/third_party_ffmpeg/pulls/71>
3.0.x<https://gitee.com/openharmony/third_party_ffmpeg/pulls/72>
1.1.x<https://gitee.com/openharmony/device_hisilicon_third_party_ffmpeg/pulls/18>
CVE-2022-4662
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.5-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/608>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/609>
CVE-2022-3890
严重
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.5-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/546>
CVE-2022-20568
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.5-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/629>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/630>
Security Vulnerabilities in Feburary 2023
published Feburary 7,2023
updated Feburary 7,2023
Vulnerability ID
related Vulnerability
Vulnerability Description
Vulnerability Impact
CVSS3.1 Base Score
affected versions
affected projects
fix link
reference
OpenHarmony-SA-2023-0201
CVE-2023-0083
The ArkUI framework subsystem doesn't check the input parameter,causing type confusion and invalid memory access.
Local attackers can exploit this vulnerability to send malicious data, causing the current application to crash.
4.0
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.5-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
arkui_ace_engine
3.1.x<https://gitee.com/openharmony/arkui_ace_engine/pulls/8872>
3.0.x<https://gitee.com/openharmony/arkui_ace_engine/pulls/8877>
Reported by researchers
OpenHarmony-SA-2023-0202
CVE-2023-22301
The kernel subsystem hmdfs has a arbitrary memory accessing vulnerability.
Network attackers can launch a remote attack to obtain kernel memory data of the target system.
6.5
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.5-Release
kernel_linux_5.10
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/656>
Reported by researchers
OpenHarmony-SA-2023-0203
CVE-2023-22436
The kernel subsystem function check_permission_for_set_tokenid has an UAF vulnerability.
Local attackers can exploit this vulnerability to escalate the privilege to root.
7.8
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.5-Release
kernel_linux_5.10
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/598>
Reported by researchers
The following table lists the third-party library vulnerabilities with only the CVE, severity, and affected OpenHarmony versions provided. For more details, see the security bulletins released by third-parties.
CVE
severity
affected OpenHarmony versions
fix link
CVE-2022-2347
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/third_party_u-boot/pulls/62>
3.0.x<https://gitee.com/openharmony/third_party_u-boot/pulls/63>
CVE-2022-4135
Critical
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.5-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/546>
CVE-2022-4186
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.5-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/546>
CVE-2022-4438
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.5-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/546>
CVE-2022-4437
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.5-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/546>
CVE-2022-4436
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.5-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/546>
CVE-2022-41218
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/646>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/647>
CVE-2022-3424
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.5-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/646>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/647>
CVE-2022-4129
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/586>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/587>
CVE-2022-42328
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.5-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/646>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/647>
CVE-2022-3643
Critical
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.5-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/646>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/647>
CVE-2022-3105
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/579>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/580>
CVE-2022-3104
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/579>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/580>
CVE-2022-3115
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/579>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/580>
CVE-2022-3113
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/579>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/580>
CVE-2022-3112
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/579>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/580>
CVE-2022-3111
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/584>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/585>
CVE-2022-3108
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/586>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/587>
CVE-2022-3107
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/590>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/591>
CVE-2022-3106
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/592>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/593>
CVE-2022-47519
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/586>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/587>
CVE-2022-43551
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.5-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
OpenHarmony-v1.1.0-Release through OpenHarmony-v1.1.5-LTS
3.1.x<https://gitee.com/openharmony/third_party_curl/pulls/99>
3.0.x<https://gitee.com/openharmony/third_party_curl/pulls/100>
1.1.x<https://gitee.com/openharmony/third_party_curl/pulls/101>
CVE-2022-43552
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.5-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
OpenHarmony-v1.1.0-Release through OpenHarmony-v1.1.5-LTS
3.1.x<https://gitee.com/openharmony/third_party_curl/pulls/99>
3.0.x<https://gitee.com/openharmony/third_party_curl/pulls/100>
1.1.x<https://gitee.com/openharmony/third_party_curl/pulls/101>
CVE-2022-47518
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/586>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/587>
CVE-2022-47520
Low
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/586>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/587>
CVE-2022-47521
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/586>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/587>
CVE-2022-3109
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.5-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
OpenHarmony-v1.1.0-Release through OpenHarmony-v1.1.5-LTS
3.1.x<https://gitee.com/openharmony/third_party_ffmpeg/pulls/71>
3.0.x<https://gitee.com/openharmony/third_party_ffmpeg/pulls/72>
1.1.x<https://gitee.com/openharmony/device_hisilicon_third_party_ffmpeg/pulls/18>
CVE-2022-4662
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.5-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/608>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/609>
CVE-2022-3890
Critical
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.5-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/546>
CVE-2022-20568
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.5-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/629>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/630>
1
0

04 Jan '23
2023年01月安全漏洞
发布于2022.01.03
最后更新于2022.01.03
漏洞编号
相关漏洞
漏洞描述
漏洞影响
CVSS3.1基础得分
受影响的版本
受影响的仓库
修复链接
参考链接
OpenHarmony-SA-2023-0101
CVE-2023-0035
通信子系统软总线部件softbus_client_stub存在校验绕过漏洞,可发起SA中继攻击。
攻击者可在本地内发起攻击,造成校验绕过,可进一步提权攻击其他SA。
6.5
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
communication_dsoftbus
3.0.x<https://gitee.com/openharmony/communication_dsoftbus/pulls/2140>
本项目组上报
OpenHarmony-SA-2023-0102
CVE-2023-0036
杂散子系统输入法部件platform_callback_stub存在校验绕过漏洞,可发起SA中继攻击。
攻击者可在本地内发起攻击,造成校验绕过,可进一步提权攻击其他SA。
6.5
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
inputmethod_imf
3.0.x<https://gitee.com/openharmony/inputmethod_imf/pulls/228>
本项目组上报
以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本,详细信息请参考三方公告。
CVE
严重程度
受影响的OpenHarmony版本
修复链接
CVE-2021-3782
严重
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.0.x<https://gitee.com/openharmony/third_party_wayland_standard/pulls/22>
CVE-2022-3046
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.3-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/349>
CVE-2022-3041
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.3-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/349>
CVE-2022-3040
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.3-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/349>
CVE-2022-3039
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.3-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/349>
CVE-2022-3038
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.3-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/349>
CVE-2022-3057
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.3-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/349>
CVE-2022-3195
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.3-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/349>
CVE-2022-3054
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.3-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/349>
CVE-2022-3075
严重
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.3-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/349>
CVE-2022-3373
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/464>
CVE-2022-3370
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/464>
CVE-2022-3311
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/464>
CVE-2022-3316
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/464>
CVE-2022-3315
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/464>
CVE-2022-3304
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/464>
CVE-2022-43680
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.3-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/third_party_expat/pulls/23>
3.0.x<https://gitee.com/openharmony/third_party_expat/pulls/22>
CVE-2022-32221
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/third_party_curl/pulls/91>
3.0.x<https://gitee.com/openharmony/third_party_curl/pulls/90>
CVE-2022-42916
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/third_party_curl/pulls/91>
3.0.x<https://gitee.com/openharmony/third_party_curl/pulls/90>
CVE-2022-42915
严重
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/third_party_curl/pulls/91>
3.0.x<https://gitee.com/openharmony/third_party_curl/pulls/90>
CVE-2022-44638
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/third_party_pixman/pulls/11>
3.0.x<https://gitee.com/openharmony/third_party_pixman/pulls/12>
CVE-2022-40284
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
3.1.x<https://gitee.com/openharmony/third_party_ntfs-3g/pulls/33>
CVE-2022-40303
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/third_party_libxml2/pulls/31>
3.0.x<https://gitee.com/openharmony/third_party_libxml2/pulls/32>
CVE-2022-40304
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/third_party_libxml2/pulls/31>
3.0.x<https://gitee.com/openharmony/third_party_libxml2/pulls/32>
CVE-2022-37454
严重
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
3.1.x<https://gitee.com/openharmony/third_party_python/pulls/35>
CVE-2022-42919
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
3.1.x<https://gitee.com/openharmony/third_party_python/pulls/36>
CVE-2022-45061
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
3.1.x<https://gitee.com/openharmony/third_party_python/pulls/37>
CVE-2020-10735
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.3-Release
3.1.x<https://gitee.com/openharmony/third_party_python/pulls/26>
CVE-2022-3169
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/553>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/561>
CVE-2022-42895
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/544>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/545>
CVE-2022-42896
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/544>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/545>
CVE-2022-41858
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/569>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/570>
CVE-2022-45934
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/586>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/587>
CVE-2022-4139
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/567>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/568>
CVE-2022-20566
低
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/582>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/583>
CVE-2022-4378
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/586>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/587>
Security Vulnerabilities in January 2023
published January 3,2023
updated January 3,2023
Vulnerability ID
related Vulnerability
Vulnerability Description
Vulnerability Impact
CVSS3.1 Base Score
affected versions
affected projects
fix link
reference
OpenHarmony-SA-2023-0101
CVE-2023-0035
softbus_client_stub in communication subsystem has an authentication bypass vulnerability which allows an "SA relay attack".
Local attackers can bypass authentication and attack other SAs with high privilege.
6.5
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
communication_dsoftbus
3.0.x<https://gitee.com/openharmony/communication_dsoftbus/pulls/2140>
Reported by OpenHarmony Team
OpenHarmony-SA-2023-0102
CVE-2023-0036
platform_callback_stub in misc subsystem has an authentication bypass vulnerability which allows an "SA relay attack".
Local attackers can bypass authentication and attack other SAs with high privilege.
6.5
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
inputmethod_imf
3.0.x<https://gitee.com/openharmony/inputmethod_imf/pulls/228>
Reported by OpenHarmony Team
The following table lists the third-party library vulnerabilities with only the CVE, severity, and affected OpenHarmony versions provided. For more details, see the security bulletins released by third-parties.
CVE
severity
affected OpenHarmony versions
fix link
CVE-2021-3782
Critical
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.0.x<https://gitee.com/openharmony/third_party_wayland_standard/pulls/22>
CVE-2022-3046
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.3-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/349>
CVE-2022-3041
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.3-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/349>
CVE-2022-3040
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.3-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/349>
CVE-2022-3039
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.3-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/349>
CVE-2022-3038
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.3-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/349>
CVE-2022-3057
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.3-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/349>
CVE-2022-3195
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.3-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/349>
CVE-2022-3054
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.3-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/349>
CVE-2022-3075
Critical
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.3-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/349>
CVE-2022-3373
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/464>
CVE-2022-3370
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/464>
CVE-2022-3311
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/464>
CVE-2022-3316
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/464>
CVE-2022-3315
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/464>
CVE-2022-3304
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/464>
CVE-2022-43680
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.3-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/third_party_expat/pulls/23>
3.0.x<https://gitee.com/openharmony/third_party_expat/pulls/22>
CVE-2022-32221
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/third_party_curl/pulls/91>
3.0.x<https://gitee.com/openharmony/third_party_curl/pulls/90>
CVE-2022-42916
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/third_party_curl/pulls/91>
3.0.x<https://gitee.com/openharmony/third_party_curl/pulls/90>
CVE-2022-42915
Critical
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/third_party_curl/pulls/91>
3.0.x<https://gitee.com/openharmony/third_party_curl/pulls/90>
CVE-2022-44638
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/third_party_pixman/pulls/11>
3.0.x<https://gitee.com/openharmony/third_party_pixman/pulls/12>
CVE-2022-40284
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
3.1.x<https://gitee.com/openharmony/third_party_ntfs-3g/pulls/33>
CVE-2022-40303
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/third_party_libxml2/pulls/31>
3.0.x<https://gitee.com/openharmony/third_party_libxml2/pulls/32>
CVE-2022-40304
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/third_party_libxml2/pulls/31>
3.0.x<https://gitee.com/openharmony/third_party_libxml2/pulls/32>
CVE-2022-37454
Critical
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
3.1.x<https://gitee.com/openharmony/third_party_python/pulls/35>
CVE-2022-42919
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
3.1.x<https://gitee.com/openharmony/third_party_python/pulls/36>
CVE-2022-45061
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
3.1.x<https://gitee.com/openharmony/third_party_python/pulls/37>
CVE-2020-10735
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.3-Release
3.1.x<https://gitee.com/openharmony/third_party_python/pulls/26>
CVE-2022-3169
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/553>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/561>
CVE-2022-42895
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/544>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/545>
CVE-2022-42896
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/544>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/545>
CVE-2022-41858
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/569>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/570>
CVE-2022-45934
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/586>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/587>
CVE-2022-4139
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/567>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/568>
CVE-2022-20566
Low
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/582>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/583>
CVE-2022-4378
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.7-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/586>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/587>
1
0

06 Dec '22
2022年12月安全漏洞
发布于2022.12.06
最后更新于2022.12.06
漏洞编号
相关漏洞
漏洞描述
漏洞影响
CVSS3.1基础得分
受影响的版本
受影响的仓库
修复链接
参考链接
OpenHarmony-SA-2022-1201
CVE-2022-45877
跨设备认证中pin码会明文传输到对端设备进行校验,会降低中间人攻击的难度。
攻击者可在局域网发起攻击,绕过权限管控机制,降低中间人攻击的难度。
8.3
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
distributedhardware_device_manager
applications_hap
security_device_auth
3.1.x<https://gitee.com/openharmony/distributedhardware_device_manager/pulls/915>
3.1.x<https://gitee.com/openharmony/applications_hap/pulls/1364>
3.1.x<https://gitee.com/openharmony/security_device_auth/pulls/351>
本项目组上报
OpenHarmony-SA-2022-1202
CVE-2022-41802
内核子系统kernel_liteos_a中系统调用SysClockGetres存在泄漏内核栈的漏洞。
攻击者可在本地发起攻击,导致编译器自动填充的4字节数据被误拷贝到用户空间,造成内核栈上泄漏4字节内容。
4.0
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
OpenHarmony-v1.1.0-LTS到OpenHarmony-v1.1.5-LTS
kernel_liteos_a
3.1.x<https://gitee.com/openharmony/kernel_liteos_a/pulls/1065>
3.0.x<https://gitee.com/openharmony/kernel_liteos_a/pulls/1066>
1.1.x<https://gitee.com/openharmony/kernel_liteos_a/pulls/1075>
研究者上报
OpenHarmony-SA-2022-1203
CVE-2022-45126
内核子系统kernel_liteos_a中系统调用SysClockGettime存在泄漏内核栈的漏洞。
攻击者可在本地发起攻击,导致编译器自动填充的4字节数据被误拷贝到用户空间,造成内核栈上泄漏4字节内容。
4.0
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
OpenHarmony-v1.1.0-LTS到OpenHarmony-v1.1.5-LTS
kernel_liteos_a
3.1.x<https://gitee.com/openharmony/kernel_liteos_a/pulls/1065>
3.0.x<https://gitee.com/openharmony/kernel_liteos_a/pulls/1066>
1.1.x<https://gitee.com/openharmony/kernel_liteos_a/pulls/1075>
研究者上报
OpenHarmony-SA-2022-1204
CVE-2022-43662
内核子系统kernel_liteos_a中系统调用SysTimerGettime存在泄漏内核栈的漏洞。
攻击者可在本地发起攻击,导致编译器自动填充的4字节数据被误拷贝到用户空间,造成内核栈上泄漏4字节内容。
4.0
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
OpenHarmony-v1.1.0-LTS到OpenHarmony-v1.1.5-LTS
kernel_liteos_a
3.1.x<https://gitee.com/openharmony/kernel_liteos_a/pulls/1065>
3.0.x<https://gitee.com/openharmony/kernel_liteos_a/pulls/1066>
1.1.x<https://gitee.com/openharmony/kernel_liteos_a/pulls/1075>
研究者上报
OpenHarmony-SA-2022-1205
CVE-2022-44455
appspawn and nwebspawn服务 对输入缺少校验,存在内存溢出漏洞。
攻击者可在本地发起攻击,恶意应用可以提升权限或造成应用崩溃。
6.8
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
startup_appspawn
3.1.x<https://gitee.com/openharmony/startup_appspawn/pulls/361>
3.0.x<https://gitee.com/openharmony/startup_appspawn/pulls/426>
本项目组上报
OpenHarmony-SA-2022-1206
CVE-2022-45118
通信子系统telephony发送公共事件时带有个人数据,但缺少权限设置。
攻击者可在本地发起攻击,恶意应用可以无权限监听广播获取手机号、短信数据等信息。
6.2
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
telephony_state_registry
telephony_sms_mms
3.1.x<https://gitee.com/openharmony/telephony_state_registry/pulls/224>
3.1.x<https://gitee.com/openharmony/telephony_sms_mms/pulls/615>
本项目组上报
以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本,详细信息请参考三方公告。
CVE
严重程度
受影响的OpenHarmony版本
修复链接
CVE-2022-20422
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/509>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/508>
CVE-2022-3303
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/509>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/508>
CVE-2022-42703
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/509>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/508>
CVE-2022-41222
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/509>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/508>
CVE-2022-3239
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/509>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/508>
CVE-2022-20423
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/509>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/508>
CVE-2022-41850
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/509>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/508>
CVE-2022-3586
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/541>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/537>
CVE-2022-3625
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/541>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/537>
CVE-2022-42432
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/541>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/537>
CVE-2022-3633
低
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/541>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/537>
CVE-2022-3635
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/541>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/537>
CVE-2022-3629
低
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/541>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/537>
CVE-2022-3623
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/541>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/537>
CVE-2022-3646
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/541>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/537>
CVE-2022-3621
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/541>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/537>
CVE-2022-3567
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/541>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/537>
CVE-2022-43750
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/541>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/537>
CVE-2022-3545
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/541>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/537>
CVE-2022-3523
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/541>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/537>
CVE-2022-2602
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/541>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/537>
CVE-2022-3628
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/541>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/537>
CVE-2022-40768
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/505>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/506>
CVE-2022-3566
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/505>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/506>
CVE-2022-3577
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/505>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/506>
CVE-2022-3606
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/505>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/506>
CVE-2022-3649
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/505>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/506>
CVE-2022-3564
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/505>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/506>
CVE-2022-20409
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/505>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/506>
CVE-2022-41849
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.3-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/502>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/503>
CVE-2022-20421
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.3-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/502>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/503>
CVE-2022-3435
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.3-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/502>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/503>
CVE-2022-42719
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.3-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/502>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/503>
CVE-2022-42720
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.3-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/502>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/503>
CVE-2022-42721
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.3-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/502>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/503>
CVE-2022-42722
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.3-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/502>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/503>
CVE-2022-41674
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.3-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/502>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/503>
CVE-2022-3535
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.3-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/502>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/503>
CVE-2022-3521
低
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.3-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/502>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/503>
CVE-2022-3524
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.3-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/502>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/503>
CVE-2022-3534
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.3-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/502>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/503>
CVE-2022-3542
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.3-Release
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/502>
CVE-2022-3565
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.3-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/502>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/503>
CVE-2022-3594
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.3-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/502>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/503>
Security Vulnerabilities in December 2022
published December 6,2022
updated December 6,2022
Vulnerability ID
related Vulnerability
Vulnerability Description
Vulnerability Impact
CVSS3.1 Base Score
affected versions
affected projects
fix link
reference
OpenHarmony-SA-2022-1201
CVE-2022-45877
PIN code is transmitted to the peer device in plain text during cross-device authentication, which reduces the difficulty of man-in-the-middle attacks.
Network attackers can bypass the authentication, which reduces the difficulty of man-in-the-middle attacks.
8.3
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
distributedhardware_device_manager
applications_hap
security_device_auth
3.1.x<https://gitee.com/openharmony/distributedhardware_device_manager/pulls/915>
3.1.x<https://gitee.com/openharmony/applications_hap/pulls/1364>
3.1.x<https://gitee.com/openharmony/security_device_auth/pulls/351>
Reported by OpenHarmony Team
OpenHarmony-SA-2022-1202
CVE-2022-41802
Kernel subsystem in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGetres.
4 bytes padding data from kernel stack are copied to user space incorrectly and leaked.
4.0
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
OpenHarmony-v1.1.0-LTS through OpenHarmony-v1.1.5-LTS
kernel_liteos_a
3.1.x<https://gitee.com/openharmony/kernel_liteos_a/pulls/1065>
3.0.x<https://gitee.com/openharmony/kernel_liteos_a/pulls/1066>
1.1.x<https://gitee.com/openharmony/kernel_liteos_a/pulls/1075>
Reported by Researchers
OpenHarmony-SA-2022-1203
CVE-2022-45126
Kernel subsystem in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGettime.
4 bytes padding data from kernel stack are copied to user space incorrectly and leaked.
4.0
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
OpenHarmony-v1.1.0-LTS through OpenHarmony-v1.1.5-LTS
kernel_liteos_a
3.1.x<https://gitee.com/openharmony/kernel_liteos_a/pulls/1065>
3.0.x<https://gitee.com/openharmony/kernel_liteos_a/pulls/1066>
1.1.x<https://gitee.com/openharmony/kernel_liteos_a/pulls/1075>
Reported by Researchers
OpenHarmony-SA-2022-1204
CVE-2022-43662
Kernel subsystem in kernel_liteos_a has a kernel stack overflow vulnerability when call SysTimerGettime.
4 bytes padding data from kernel stack are copied to user space incorrectly and leaked.
4.0
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
OpenHarmony-v1.1.0-LTS through OpenHarmony-v1.1.5-LTS
kernel_liteos_a
3.1.x<https://gitee.com/openharmony/kernel_liteos_a/pulls/1065>
3.0.x<https://gitee.com/openharmony/kernel_liteos_a/pulls/1066>
1.1.x<https://gitee.com/openharmony/kernel_liteos_a/pulls/1075>
Reported by Researchers
OpenHarmony-SA-2022-1205
CVE-2022-44455
The appspawn and nwebspawn services were found to be vulnerable to buffer overflow vulnerability due to insufficient input validation.
An unprivileged malicious application would be able to gain code execution within any application installed on the device or cause application crash.
6.8
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
startup_appspawn
3.1.x<https://gitee.com/openharmony/startup_appspawn/pulls/361>
3.0.x<https://gitee.com/openharmony/startup_appspawn/pulls/426>
Reported by OpenHarmony Team
OpenHarmony-SA-2022-1206
CVE-2022-45118
Telephony in communication subsystem sends public events with personal data, but the permission is not set.
Malicious apps could listen to public events and obtain information such as mobile numbers and SMS data without permissions.
6.2
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
telephony_state_registry
telephony_sms_mms
3.1.x<https://gitee.com/openharmony/telephony_state_registry/pulls/224>
3.1.x<https://gitee.com/openharmony/telephony_sms_mms/pulls/615>
Reported by OpenHarmony Team
The following table lists the third-party library vulnerabilities with only the CVE, severity, and affected OpenHarmony versions provided. For more details, see the security bulletins released by third-parties.
CVE
severity
affected OpenHarmony versions
fix link
CVE-2022-20422
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/509>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/508>
CVE-2022-3303
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/509>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/508>
CVE-2022-42703
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/509>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/508>
CVE-2022-41222
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/509>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/508>
CVE-2022-3239
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/509>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/508>
CVE-2022-20423
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/509>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/508>
CVE-2022-41850
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/509>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/508>
CVE-2022-3586
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/541>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/537>
CVE-2022-3625
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/541>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/537>
CVE-2022-42432
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/541>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/537>
CVE-2022-3633
Low
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/541>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/537>
CVE-2022-3635
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/541>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/537>
CVE-2022-3629
Low
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/541>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/537>
CVE-2022-3623
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/541>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/537>
CVE-2022-3646
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/541>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/537>
CVE-2022-3621
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/541>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/537>
CVE-2022-3567
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/541>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/537>
CVE-2022-43750
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/541>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/537>
CVE-2022-3545
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/541>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/537>
CVE-2022-3523
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/541>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/537>
CVE-2022-2602
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/541>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/537>
CVE-2022-3628
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/541>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/537>
CVE-2022-40768
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/505>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/506>
CVE-2022-3566
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/505>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/506>
CVE-2022-3577
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/505>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/506>
CVE-2022-3606
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/505>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/506>
CVE-2022-3649
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/505>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/506>
CVE-2022-3564
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/505>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/506>
CVE-2022-20409
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.4-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/505>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/506>
CVE-2022-41849
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.3-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/502>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/503>
CVE-2022-20421
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.3-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/502>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/503>
CVE-2022-3435
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.3-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/502>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/503>
CVE-2022-42719
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.3-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/502>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/503>
CVE-2022-42720
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.3-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/502>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/503>
CVE-2022-42721
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.3-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/502>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/503>
CVE-2022-42722
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.3-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/502>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/503>
CVE-2022-41674
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.3-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/502>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/503>
CVE-2022-3535
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.3-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/502>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/503>
CVE-2022-3521
Low
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.3-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/502>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/503>
CVE-2022-3524
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.3-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/502>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/503>
CVE-2022-3534
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.3-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/502>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/503>
CVE-2022-3542
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.3-Release
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/502>
CVE-2022-3565
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.3-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/502>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/503>
CVE-2022-3594
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.3-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/502>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/503>
1
0

01 Nov '22
2022年11月安全漏洞
发布于2022.11.1
最后更新于2022.11.11
漏洞编号
相关漏洞
漏洞描述
漏洞影响
CVSS3.1基础得分
受影响的版本
受影响的仓库
修复链接
参考链接
OpenHarmony-SA-2022-1101
CVE-2022-43451
启动子系统appspawn和nwebspawn服务存在路径穿越漏洞。
攻击者可在本地发起攻击,造成任意路径穿越,可穿越沙箱。如果结合其他漏洞可进一步获取root权限。
8.4
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
startup_appspawn
3.1.x<https://gitee.com/openharmony/startup_appspawn/pulls/361>
本项目组上报
OpenHarmony-SA-2022-1102
CVE-2022-43449
download_server存在任意文件读取漏洞。
攻击者可在本地发起攻击,读取文件系统上任意可被download_server访问的文件。
6.2
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
request_request
3.1.x<https://gitee.com/openharmony/request_request/pulls/207>
本项目组上报
OpenHarmony-SA-2022-1103
CVE-2022-43495
distributedhardware_device_manage在设备组网过程中收到异常报文会导致设备重启。
攻击者可在局域网发起攻击,在设备组网过程中,发送恶意报文,可造成空指针解引用,设备重启。
6.5
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
distributedhardware_device_manager
3.1.x<https://gitee.com/openharmony/distributedhardware_device_manager/pulls/728>
本项目组上报
以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本,详细信息请参考三方公告。
CVE
严重程度
受影响的OpenHarmony版本
修复链接
CVE-2022-2295
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/third_party_chromium/pulls/31>
CVE-2022-2294
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/third_party_chromium/pulls/31>
CVE-2022-26373
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/461>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/495>
CVE-2022-23816
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/457>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/494>
CVE-2022-29901
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/457>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/494>
CVE-2022-29900
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/457>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/494>
CVE-2022-2481
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/third_party_chromium/pulls/31>
CVE-2022-2480
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/third_party_chromium/pulls/31>
CVE-2022-2478
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/third_party_chromium/pulls/31>
CVE-2022-2477
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/third_party_chromium/pulls/31>
CVE-2022-30790
严重
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
OpenHarmony-v1.1.0-Release到OpenHarmony-v1.1.4-LTS
3.1.x<https://gitee.com/openharmony/third_party_u-boot/pulls/50>
3.1.x<https://gitee.com/openharmony/device_soc_hisilicon/pulls/247>
3.0.x<https://gitee.com/openharmony/third_party_u-boot/pulls/49>
3.0.x<https://gitee.com/openharmony/device_hisilicon_hi3516dv300/pulls/86/files>
1.1.x<https://gitee.com/openharmony/third_party_u-boot/pulls/48>
CVE-2022-1462
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/449>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/490>
CVE-2022-1184
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.3-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<http://gitee.com/openharmony/kernel_linux_5.10/pulls/474>
3.0.x<http://gitee.com/openharmony/kernel_linux_5.10/pulls/475>
CVE-2022-2663
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/445>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/489>
CVE-2022-39190
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/445>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/489>
CVE-2022-39189
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/445>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/489>
CVE-2022-40674
严重
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/third_party_expat/pulls/20>
3.0.x<https://gitee.com/openharmony/third_party_expat/pulls/19>
CVE-2022-3202
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.3-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/463>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/464>
CVE-2022-3199
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.3-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/349>
Security Vulnerabilities in November 2022
published November 1,2022
updated November 1,2022
Vulnerability ID
related Vulnerability
Vulnerability Description
Vulnerability Impact
CVSS3.1 Base Score
affected versions
affected projects
fix link
reference
OpenHarmony-SA-2022-1101
CVE-2022-43451
Multiple path traversal in appspawn and nwebspawn services.
Local attackers can create arbitrary directories or escape application sandbox.If chained with other vulnerabilities it would allow an unprivileged process to gain full root privileges.
8.4
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
startup_appspawn
3.1.x<https://gitee.com/openharmony/startup_appspawn/pulls/361>
Reported by OpenHarmony Team
OpenHarmony-SA-2022-1102
CVE-2022-43449
Arbitrary file read via download_server.
Local attackers can install an malicious application on the device and reveal any file from the filesystem that is accessible to download_server service which run with UID 1000.
6.2
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
request_request
3.1.x<https://gitee.com/openharmony/request_request/pulls/207>
Reported by OpenHarmony Team
OpenHarmony-SA-2022-1103
CVE-2022-43495
An abnormal packet recieved when distributedhardware_device_manager joining a network could cause a device reboot.
Network attakcers can send an abonormal packet when joining a network, cause a nullptr reference and device reboot.
6.5
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
distributedhardware_device_manager
3.1.x<https://gitee.com/openharmony/distributedhardware_device_manager/pulls/728>
Reported by OpenHarmony Team
The following table lists the third-party library vulnerabilities with only the CVE, severity, and affected OpenHarmony versions provided. For more details, see the security bulletins released by third-parties.
CVE
severity
affected OpenHarmony versions
fix link
CVE-2022-2295
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/third_party_chromium/pulls/31>
CVE-2022-2294
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/third_party_chromium/pulls/31>
CVE-2022-26373
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/461>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/495>
CVE-2022-23816
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/457>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/494>
CVE-2022-29901
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/457>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/494>
CVE-2022-29900
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/457>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/494>
CVE-2022-2481
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/third_party_chromium/pulls/31>
CVE-2022-2480
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/third_party_chromium/pulls/31>
CVE-2022-2478
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/third_party_chromium/pulls/31>
CVE-2022-2477
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/third_party_chromium/pulls/31>
CVE-2022-30790
Critical
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
OpenHarmony-v1.1.0-Release through OpenHarmony-v1.1.4-LTS
3.1.x<https://gitee.com/openharmony/third_party_u-boot/pulls/50>
3.1.x<https://gitee.com/openharmony/device_soc_hisilicon/pulls/247>
3.0.x<https://gitee.com/openharmony/third_party_u-boot/pulls/49>
3.0.x<https://gitee.com/openharmony/device_hisilicon_hi3516dv300/pulls/86/files>
1.1.x<https://gitee.com/openharmony/third_party_u-boot/pulls/48>
CVE-2022-1462
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/449>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/490>
CVE-2022-1184
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.3-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<http://gitee.com/openharmony/kernel_linux_5.10/pulls/474>
3.0.x<http://gitee.com/openharmony/kernel_linux_5.10/pulls/475>
CVE-2022-2663
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/445>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/489>
CVE-2022-39190
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/445>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/489>
CVE-2022-39189
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/445>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/489>
CVE-2022-40674
Critical
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/third_party_expat/pulls/20>
3.0.x<https://gitee.com/openharmony/third_party_expat/pulls/19>
CVE-2022-3202
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.3-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/463>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/464>
CVE-2022-3199
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.3-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/349>
1
0
Security Vulnerabilities in October 2022
published October 11,2022
updated October 11,2022
Vulnerability ID
related Vulnerability
Vulnerability Description
Vulnerability Impact
CVSS3.1 Base Score
affected versions
affected projects
fix link
reference
OpenHarmony-SA-2022-1001
CVE-2022-42488
Startup subsystem missed permission validation in param service.
Local attackers can install an malicious application on the device to elevate its privileges to the root user, disable security features, or cause DoS by disabling particular services.
8.4
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
startup_init_lite
3.1.x<https://gitee.com/openharmony/startup_init_lite/pulls/1104>
3.1.x<https://gitee.com/openharmony/startup_init_lite/pulls/1074>
Reported by OpenHarmony Team
OpenHarmony-SA-2022-1002
CVE-2022-42464
Kernel memory pool override in /dev/mmz_userdev device driver
If the processes with system UID run on the device, local attackers would be able to mmap memory pools used by kernel and override them which could be used to gain kernel code execution on the device, gain root privileges, or cause device reboot.
6.7
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
device_board_hisilicon
device_hisilicon_hi3516dv300
3.0.x<https://gitee.com/openharmony/device_board_hisilicon/pulls/135>
3.1.x<https://gitee.com/openharmony/device_hisilicon_hi3516dv300/pulls/87>
Reported by OpenHarmony Team
OpenHarmony-SA-2022-1003
CVE-2022-41686
Out-of-bound memory read and write in /dev/mmz_userdev device driver.
If the processes with system user UID run on the device, local attackers would be able to write out-of-bound memory which could lead to unspecified memory corruption.
5.1
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
device_board_hisilicon
device_hisilicon_hispark_taurus
3.1.x<https://gitee.com/openharmony/device_soc_hisilicon/pulls/287>
3.0.x<https://gitee.com/openharmony/device_hisilicon_hispark_taurus/pulls/127>
Reported by OpenHarmony Team
OpenHarmony-SA-2022-1004
CVE-2022-42463
Softbus_server in communication subsystem has an authentication bypass vulnerability in a callback handler function.
Attackers can launch attacks on distributed networks by sending Bluetooth rfcomm packets to any remote device and executing arbitrary commands.
8.3
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
communication_dsoftbus
3.1.x<https://gitee.com/openharmony/communication_dsoftbus/pulls/2348>
Reported by OpenHarmony Team
The following table lists the third-party library vulnerabilities with only the CVE, severity, and affected OpenHarmony versions provided. For more details, see the security bulletins released by third-parties.
CVE
severity
affected OpenHarmony versions
fix link
CVE-2022-27405
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
OpenHarmony-v1.1.0-release through OpenHarmony-v1.1.5-LTS
3.1.x<https://gitee.com/openharmony/third_party_freetype/pulls/32>
3.0.x<https://gitee.com/openharmony/third_party_freetype/pulls/31>
1.1.x<https://gitee.com/openharmony/third_party_freetype/pulls/30>
CVE-2022-2959
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/428>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/436>
CVE-2022-2991
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/428>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/436>
CVE-2022-2938
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/430>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/434>
CVE-2022-2586
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/427>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/402>
CVE-2022-2588
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/426>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/402>
CVE-2022-2585
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/426>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/402>
CVE-2022-2503
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/431>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/435>
CVE-2022-20369
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/426>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/402>
CVE-2022-20368
Critical
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/426>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/402>
CVE-2022-2639
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/423>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/392>
CVE-2022-36123
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/426>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/402>
CVE-2022-36946
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/423>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/392>
CVE-2022-36879
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/423>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/369>
CVE-2022-2327
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/423>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/392>
CVE-2022-21505
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/423>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/368>
CVE-2021-33655
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/423>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/392>
CVE-2021-33656
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/437>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/369>
CVE-2022-2861
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/274>
CVE-2022-2860
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/274>
CVE-2022-2613
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/274>
CVE-2022-2612
Low
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/274>
CVE-2022-2610
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/274>
CVE-2022-2607
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/274>
CVE-2022-2606
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/274>
CVE-2022-2624
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/274>
CVE-2022-2623
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/274>
CVE-2022-2620
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/274>
CVE-2022-2619
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/274>
CVE-2022-2617
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/274>
CVE-2022-2616
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/274>
CVE-2022-2615
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/274>
CVE-2022-2614
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/274>
CVE-2022-35737
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x<https://gitee.com/openharmony/third_party_sqlite/pulls/38>
3.0.x<https://gitee.com/openharmony/third_party_sqlite/pulls/37>
CVE-2022-2415
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/third_party_chromium/pulls/35>
CVE-2022-1919
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/third_party_chromium/pulls/35>
CVE-2022-35252
Low
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
OpenHarmony-v1.1.0-release through OpenHarmony-v1.1.5-LTS
3.1.x<https://gitee.com/openharmony/third_party_curl/pulls/83>
3.0.x<https://gitee.com/openharmony/third_party_curl/pulls/85>
1.1.x<https://gitee.com/openharmony/third_party_curl/pulls/86>
CVE-2022-3028
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/440>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/442>
CVE-2022-2977
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/440>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/442>
CVE-2022-2964
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/440>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/442>
CVE-2022-39188
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/450>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/477>
CVE-2022-3078
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/450>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/477>
CVE-2022-2905
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/450>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/477>
CVE-2022-39842
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/450>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/477>
CVE-2022-3061
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/443>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/444>
CVE-2021-29921
Critical
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/third_party_python/pulls/19>
CVE-2022-0391
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/third_party_python/pulls/23>
CVE-2021-3737
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/third_party_python/pulls/20>
CVE-2021-4189
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/third_party_python/pulls/21>
CVE-2021-3733
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/third_party_python/pulls/22>
CVE-2021-28861
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/third_party_python/pulls/24>
CVE-2022-40307
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.3-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/463>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/464>
1
0

11 Oct '22
2022年10月安全漏洞
发布于2022.10.11
最后更新于2022.10.11
漏洞编号
相关漏洞
漏洞描述
漏洞影响
CVSS3.1基础得分
受影响的版本
受影响的仓库
修复链接
参考链接
OpenHarmony-SA-2022-1001
CVE-2022-42488
启动子系统param服务缺少权限校验。
攻击者可在本地发起攻击,获取root权限,关闭安全特性或对任意服务造成DoS攻击。
8.4
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
startup_init_lite
3.1.x<https://gitee.com/openharmony/startup_init_lite/pulls/1104>
3.1.x<https://gitee.com/openharmony/startup_init_lite/pulls/1074>
本项目组上报
OpenHarmony-SA-2022-1002
CVE-2022-42464
dev/mmz_userdev驱动存在内核内存非法映射漏洞。
攻击者可在本地发起攻击,非法映射内存并进行读写,可提升到root权限或造成设备重启。利用此漏洞需要system UID。
6.7
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
device_board_hisilicon
device_hisilicon_hi3516dv300
3.1.x<https://gitee.com/openharmony/device_board_hisilicon/pulls/135>
3.0.x<https://gitee.com/openharmony/device_hisilicon_hi3516dv300/pulls/87>
本项目组上报
OpenHarmony-SA-2022-1003
CVE-2022-41686
dev/mmz_userdev驱动存在越界读写漏洞。
攻击者可在本地发起攻击,越界读写内存地址,造成内存泄露或崩溃。利用此漏洞需要system UID。
5.1
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
device_board_hisilicon
device_hisilicon_hispark_taurus
3.1.x<https://gitee.com/openharmony/device_soc_hisilicon/pulls/287>
3.0.x<https://gitee.com/openharmony/device_hisilicon_hispark_taurus/pulls/127>
本项目组上报
OpenHarmony-SA-2022-1004
CVE-2022-42463
通信子系统softbus_server服务的一个回调处理函数存在无需认证和加密的漏洞。
攻击者可以在分布式网络发起攻击,发送蓝牙rfcomm报文到任意远程设备,执行任意命令。
8.3
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
communication_dsoftbus
3.1.x<https://gitee.com/openharmony/communication_dsoftbus/pulls/2348>
本项目组上报
以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本,详细信息请参考三方公告。
CVE
严重程度
受影响的OpenHarmony版本
修复链接
CVE-2022-27405
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
OpenHarmony-v1.1.0-release到OpenHarmony-v1.1.5-LTS
3.1.x<https://gitee.com/openharmony/third_party_freetype/pulls/32>
3.0.x<https://gitee.com/openharmony/third_party_freetype/pulls/31>
1.1.x<https://gitee.com/openharmony/third_party_freetype/pulls/30>
CVE-2022-2959
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/428>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/436>
CVE-2022-2991
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/428>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/436>
CVE-2022-2938
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/430>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/434>
CVE-2022-2586
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/427>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/402>
CVE-2022-2588
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/426>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/402>
CVE-2022-2585
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/426>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/402>
CVE-2022-2503
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/431>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/435>
CVE-2022-20369
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/426>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/402>
CVE-2022-20368
严重
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/426>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/402>
CVE-2022-2639
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/423>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/392>
CVE-2022-36123
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/426>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/402>
CVE-2022-36946
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/423>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/392>
CVE-2022-36879
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/423>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/369>
CVE-2022-2327
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/423>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/392>
CVE-2022-21505
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/423>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/368>
CVE-2021-33655
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/423>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/392>
CVE-2021-33656
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/437>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/369>
CVE-2022-2861
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/274>
CVE-2022-2860
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/274>
CVE-2022-2613
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/274>
CVE-2022-2612
低
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/274>
CVE-2022-2610
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/274>
CVE-2022-2607
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/274>
CVE-2022-2606
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/274>
CVE-2022-2624
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/274>
CVE-2022-2623
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/274>
CVE-2022-2620
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/274>
CVE-2022-2619
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/274>
CVE-2022-2617
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/274>
CVE-2022-2616
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/274>
CVE-2022-2615
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/274>
CVE-2022-2614
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/web_webview/pulls/274>
CVE-2022-35737
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x<https://gitee.com/openharmony/third_party_sqlite/pulls/38>
3.0.x<https://gitee.com/openharmony/third_party_sqlite/pulls/37>
CVE-2022-2415
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/third_party_chromium/pulls/35>
CVE-2022-1919
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/third_party_chromium/pulls/35>
CVE-2022-35252
低
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
OpenHarmony-v1.1.0-release到OpenHarmony-v1.1.5-LTS
3.1.x<https://gitee.com/openharmony/third_party_curl/pulls/83>
3.0.x<https://gitee.com/openharmony/third_party_curl/pulls/85>
1.1.x<https://gitee.com/openharmony/third_party_curl/pulls/86>
CVE-2022-3028
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/440>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/442>
CVE-2022-2977
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/440>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/442>
CVE-2022-2964
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/440>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/442>
CVE-2022-39188
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/450>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/477>
CVE-2022-3078
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/450>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/477>
CVE-2022-2905
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/450>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/477>
CVE-2022-39842
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/450>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/477>
CVE-2022-3061
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/443>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/444>
CVE-2021-29921
严重
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/third_party_python/pulls/19>
CVE-2022-0391
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/third_party_python/pulls/23>
CVE-2021-3737
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/third_party_python/pulls/20>
CVE-2021-4189
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/third_party_python/pulls/21>
CVE-2021-3733
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/third_party_python/pulls/22>
CVE-2021-28861
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
3.1.x<https://gitee.com/openharmony/third_party_python/pulls/24>
CVE-2022-40307
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.3-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.6-LTS
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/463>
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/464>
1
0

OpenHarmony2022年9月安全漏洞 OpenHarmony Security Vulnerabilities in September 2022
by OpenHarmony-CNA 06 Sep '22
by OpenHarmony-CNA 06 Sep '22
06 Sep '22
2022年9月安全漏洞
发布于2022.9.6
最后更新于2022.9.6
漏洞编号
相关漏洞
漏洞描述
漏洞影响
CVSS3.1基础得分
受影响的版本
受影响的仓库
修复链接
参考链接
OpenHarmony-SA-2022-0901
CVE-2022-36423
cJSON库的错误配置,导致递归解析时存在栈溢出漏洞。
攻击者可在局域网络内发起攻击,对网络内设备发起DoS攻击,导致进程崩溃。
7.4
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
OpenHarmony-v1.1.0-LTS到OpenHarmony-v1.1.5-LTS
third_party_cJSON
3.1.x
3.1.x
3.0.x
3.0.x
1.1.x
1.1.x
本项目组上报
OpenHarmony-SA-2022-0902
CVE-2022-38081
安全子系统tokensync系统服务存在对调用者的权限校验绕过漏洞。
攻击者可在局域网络内发起攻击,绕过分布式调用权限管控。利用此漏洞需要额外的一个获取system权限的漏洞。
6.2
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
security_access_token
3.1.x
本项目组上报
OpenHarmony-SA-2022-0903
CVE-2022-38701
通信子系统分布式软总线模块ipc接口存在堆内存泄露漏洞。
攻击者可在局域网络内发起攻击,绕过分布式调用权限管控。
6.2
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
communication_dsoftbus
3.1.x
3.0.x
本项目组上报
OpenHarmony-SA-2022-0904
CVE-2022-38064
windowmanager的系统服务存在对调用者的权限校验绕过漏洞。
攻击者可在本地发起攻击,绕过权限管控机制,获取设备敏感信息。
6.2
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
windowmanager
3.1.x
本项目组上报
OpenHarmony-SA-2022-0905
CVE-2022-38700
多媒体子系统相机服务存在对调用者的权限校验绕过漏洞。
攻击者可在局域网内发起攻击,绕过权限管控机制,访问相机服务。
8.8
OpenHarmony-v3.1-Release
multimedia_camera_standard
3.1.x
本项目组上报
以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本,详细信息请参考三方公告。
CVE
严重程度
受影响的OpenHarmony版本
修复链接
CVE-2022-34918
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-33981
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
3.1.x
CVE-2022-33743
低
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.0.x
CVE-2022-33742
低
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.0.x
CVE-2022-33741
低
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.0.x
CVE-2022-33740
低
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.0.x
CVE-2022-32981
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-32296
低
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-32250
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-29582
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.0.x
CVE-2022-27666
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x
CVE-2022-26365
低
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.0.x
CVE-2022-2380
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-2318
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-2153
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-21499
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-21166
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-21125
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-21123
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-20154
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-20153
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-20141
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.0.x
CVE-2022-20132
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-20009
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x
CVE-2022-1998
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-1975
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-1972
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-1852
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.0.x
CVE-2022-1836
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-1789
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.0.x
CVE-2022-1652
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.0.x
CVE-2022-1508
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-1205
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-1204
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-1198
中
OpenHarmony-v3.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.1.x
3.0.x
CVE-2022-0644
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.0.x
CVE-2021-45868
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x
CVE-2021-4135
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2021-33061
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2021-28713
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.0.x
CVE-2021-28712
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.0.x
CVE-2021-28711
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.0.x
CVE-2021-26401
中
OpenHarmony-v3.1-Release
3.1.x
CVE-2022-37434
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
OpenHarmony-v1.1.1-LTS到OpenHarmony-v1.1.5-LTS
3.1.x
3.0.x
1.1.x
CVE-2022-1587
严重
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
3.1.x
CVE-2022-1586
严重
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
3.1.x
CVE-2022-2097
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
3.1.x
CVE-2022-2068
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
3.1.x
CVE-2022-30789
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
3.1.x
CVE-2022-30788
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
3.1.x
CVE-2022-30787
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
3.1.x
CVE-2022-30786
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
3.1.x
CVE-2022-30785
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
3.1.x
CVE-2022-30784
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
3.1.x
CVE-2022-30783
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
3.1.x
CVE-2021-46790
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
3.1.x
CVE-2022-32215
严重
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
3.1.x
CVE-2022-32213
严重
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
3.1.x
CVE-2022-32212
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
3.1.x
CVE-2022-2097
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
3.1.x
CVE-2021-46822
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
3.1.x
CVE-2022-2122
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-1925
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-1924
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-1923
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-1922
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-1921
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-1920
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-34835
严重
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-30767
严重
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-30552
高
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-32208
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-32207
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-32206
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-32205
中
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
Security Vulnerabilities in September 2022
published September 6,2022
updated September 6,2022
Vulnerability ID
related Vulnerability
Vulnerability Description
Vulnerability Impact
CVSS3.1 Base Score
affected versions
affected projects
fix link
reference
OpenHarmony-SA-2022-0901
CVE-2022-36423
Incorrect configuration of the cJSON library lead a Stack overflow vulnerability during recursive parsing.
LAN attackers can lead a DoS attack to all network devices.
7.4
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
OpenHarmony-v1.1.0-LTS through OpenHarmony-v1.1.5-LTS
third_party_cJSON
3.1.x
3.1.x
3.0.x
3.0.x
1.1.x
1.1.x
Reported by OpenHarmony Team
OpenHarmony-SA-2022-0902
CVE-2022-38081
Tokensync in security subsystem has a permission bypass vulnerability.
LAN attackers can bypass the distributed permission control.To take advantage of this weakness, attackers need another vulnerability to obtain system.
6.2
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
security_access_token
3.1.x
Reported by OpenHarmony Team
OpenHarmony-SA-2022-0903
CVE-2022-38701
IPC in communication subsystem has a heap overflow vulnerability.
Local attackers can trigger a heap overflow and get network sensitive information.
6.2
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
communication_dsoftbus
3.1.x
3.0.x
Reported by OpenHarmony Team
OpenHarmony-SA-2022-0904
CVE-2022-38064
windowmanager in window subsystem has a permission bypass vulnerability.
Local attackers can bypass permission control and get sensitive information.
6.2
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
windowmanager
3.1.x
Reported by OpenHarmony Team
OpenHarmony-SA-2022-0905
CVE-2022-38700
multimedia subsystem has a permission bypass vulnerability.
LAN attackers can bypass permission control and get control of camera service.
8.8
OpenHarmony-v3.1-Release
multimedia_camera_standard
3.1.x
Reported by OpenHarmony Team
The following table lists the third-party library vulnerabilities with only the CVE, severity, and affected OpenHarmony versions provided. For more details, see the security bulletins released by third-parties.
CVE
severity
affected OpenHarmony versions
fix link
CVE-2022-34918
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-33981
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
3.1.x
CVE-2022-33743
Low
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.0.x
CVE-2022-33742
Low
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.0.x
CVE-2022-33741
Low
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.0.x
CVE-2022-33740
Low
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.0.x
CVE-2022-32981
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-32296
Low
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-32250
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-29582
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.0.x
CVE-2022-27666
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x
CVE-2022-26365
Low
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.0.x
CVE-2022-2380
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-2318
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-2153
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-21499
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-21166
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-21125
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-21123
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-20154
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-20153
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-20141
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.0.x
CVE-2022-20132
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-20009
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x
CVE-2022-1998
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-1975
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-1972
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-1852
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.0.x
CVE-2022-1836
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-1789
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.0.x
CVE-2022-1652
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.0.x
CVE-2022-1508
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-1205
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-1204
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-1198
Medium
OpenHarmony-v3.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.1.x
3.0.x
CVE-2022-0644
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.0.x
CVE-2021-45868
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x
CVE-2021-4135
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2021-33061
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2021-28713
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.0.x
CVE-2021-28712
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.0.x
CVE-2021-28711
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.0.x
CVE-2021-26401
Medium
OpenHarmony-v3.1-Release
3.1.x
CVE-2022-37434
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
OpenHarmony-v1.1.1-LTS through OpenHarmony-v1.1.5-LTS
3.1.x
3.0.x
1.1.x
CVE-2022-1587
Critical
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
3.1.x
CVE-2022-1586
Critical
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
3.1.x
CVE-2022-2097
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
3.1.x
CVE-2022-2068
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
3.1.x
CVE-2022-30789
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
3.1.x
CVE-2022-30788
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
3.1.x
CVE-2022-30787
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
3.1.x
CVE-2022-30786
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
3.1.x
CVE-2022-30785
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
3.1.x
CVE-2022-30784
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
3.1.x
CVE-2022-30783
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
3.1.x
CVE-2021-46790
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
3.1.x
CVE-2022-32215
Critical
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
3.1.x
CVE-2022-32213
Critical
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
3.1.x
CVE-2022-32212
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
3.1.x
CVE-2022-2097
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
3.1.x
CVE-2021-46822
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
3.1.x
CVE-2022-2122
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-1925
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-1924
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-1923
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-1922
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-1921
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-1920
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-34835
Critical
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-30767
Critical
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-30552
High
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-32208
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-32207
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-32206
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
CVE-2022-32205
Medium
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
3.1.x
3.0.x
1
0
2022年8月安全漏洞
发布于2022.8.2
漏洞编号
相关漏洞
漏洞描述
漏洞影响
受影响的版本
受影响的仓库
修复链接
参考链接
OpenHarmony-SA-2022-0801
NA
电话服务子系统telephony_sms_mms组件DecodeUCS2Data存在DoS漏洞。
攻击者可在网络内发起攻击,访问非法内存,导致进程崩溃。
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
telephony_sms_mms
3.0.x<https://gitee.com/openharmony/telephony_sms_mms/pulls/404>
3.1.x<https://gitee.com/openharmony/telephony_sms_mms/pulls/355>
本项目组上报
OpenHarmony-SA-2022-0802
NA
电话服务子系统telephony_sms_mms组件DecodeGSMData存在DoS漏洞。
攻击者可在网络内发起攻击,访问非法内存,导致进程崩溃。
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
telephony_sms_mms
3.0.x<https://gitee.com/openharmony/telephony_sms_mms/pulls/404>
3.1.x<https://gitee.com/openharmony/telephony_sms_mms/pulls/355>
本项目组上报
OpenHarmony-SA-2022-0803
NA
电话服务子系统telephony_sms_mms组件DecodeAddress存在DoS漏洞。
攻击者可在网络内发起攻击,访问非法内存,导致进程崩溃。
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
telephony_sms_mms
3.0.x<https://gitee.com/openharmony/telephony_sms_mms/pulls/404>
3.1.x<https://gitee.com/openharmony/telephony_sms_mms/pulls/355>
本项目组上报
OpenHarmony-SA-2022-0804
NA
电话服务子系统telephony_sms_mms组件Decode8bitData存在DoS漏洞。
攻击者可在网络内发起攻击,访问非法内存,导致进程崩溃。
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
telephony_sms_mms
3.0.x<https://gitee.com/openharmony/telephony_sms_mms/pulls/404>
3.1.x<https://gitee.com/openharmony/telephony_sms_mms/pulls/355>
本项目组上报
OpenHarmony-SA-2022-0806
NA
通信子系统分布式软总线组件SendMessage接口存在漏洞,导致权限管控被绕过。
攻击者可在本地发起攻击,绕过权限管控机制,进一步向局域网内设备写入任意数据。
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
communication_dsoftbus
3.0.x<https://gitee.com/openharmony/communication_dsoftbus/pulls/1668>
本项目组上报
以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本,详细信息请参考三方公告。
CVE
严重程度
受影响的OpenHarmony版本
修复链接
CVE-2022-1729
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/255>
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/299>
CVE-2022-29581
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/255>
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/299>
CVE-2022-20008
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/241>
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/214>
CVE-2022-1195
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/241>
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/214>
CVE-2022-1516
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/241>
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/214>
CVE-2022-30594
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/241>
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/214>
CVE-2022-1012
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/237>
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/224>
CVE-2022-29824
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x<https://gitee.com/openharmony/third_party_libxml2/pulls/23>
3.1.x<https://gitee.com/openharmony/third_party_libxml2/pulls/21>
CVE-2022-1475
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x<https://gitee.com/openharmony/third_party_ffmpeg/pulls/41>
3.1.x<https://gitee.com/openharmony/third_party_ffmpeg/pulls/36>
CVE-2022-27406
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
3.0.x<https://gitee.com/openharmony/third_party_freetype/pulls/17>
[3.1.x]not fixed
CVE-2022-27404
严重
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
3.0.x<https://gitee.com/openharmony/third_party_freetype/pulls/17>
[3.1.x]not fixed
CVE-2022-1974
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/260>
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/302>
CVE-2022-1734
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
OpenHarmony-v3.1-Release
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/260>
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/214>
CVE-2022-1199
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/260>
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/333>
CVE-2022-1966
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/258>
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/332>
CVE-2022-1786
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
OpenHarmony-v3.1-Release到OpenHarmony-v3.1.1-Release
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/258>
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/332>
CVE-2022-1280
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/233>
CVE-2022-45868
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/233>
Security Vulnerabilities in August 2022
published August 2,2022
Vulnerability ID
related Vulnerability
Vulnerability Descripton
Vulnerability Impact
affected versions
affected projects
fix link
reference
OpenHarmony-SA-2022-0801
NA
DecodeUCS2Data in telephony_sms_mms component of telephony subsystem, has a DoS vulnerability.
Network attackers can access illegal memory and crash the process.
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
telephony_sms_mms
3.0.x<https://gitee.com/openharmony/telephony_sms_mms/pulls/404>
3.1.x<https://gitee.com/openharmony/telephony_sms_mms/pulls/355>
Reported by OpenHarmony Team
OpenHarmony-SA-2022-0802
NA
DecodeGSMData in telephony_sms_mms component of telephony subsystem, has a DoS vulnerability.
Network attackers can access illegal memory and crash the process.
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
telephony_sms_mms
3.0.x<https://gitee.com/openharmony/telephony_sms_mms/pulls/404>
3.1.x<https://gitee.com/openharmony/telephony_sms_mms/pulls/355>
Reported by OpenHarmony Team
OpenHarmony-SA-2022-0803
NA
DecodeAddress in telephony_sms_mms component of telephony subsystem, has a DoS vulnerability.
Network attackers can access illegal memory and crash the process.
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
telephony_sms_mms
3.0.x<https://gitee.com/openharmony/telephony_sms_mms/pulls/404>
3.1.x<https://gitee.com/openharmony/telephony_sms_mms/pulls/355>
Reported by OpenHarmony Team
OpenHarmony-SA-2022-0804
NA
Decode8bitData in telephony_sms_mms component of telephony subsystem, has a DoS vulnerability.
Network attackers can access illegal memory and crash the process.
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
telephony_sms_mms
3.0.x<https://gitee.com/openharmony/telephony_sms_mms/pulls/404>
3.1.x<https://gitee.com/openharmony/telephony_sms_mms/pulls/355>
Reported by OpenHarmony Team
OpenHarmony-SA-2022-0806
NA
SendMessage in dsoftbus in communication subsystem has a permission bypass vulnerability.
Local attackers can bypass the permission check, and write any data into network devices.
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
communication_dsoftbus
3.0.x<https://gitee.com/openharmony/communication_dsoftbus/pulls/1668>
Reported by OpenHarmony Team
The following table lists the third-party library vulnerabilities with only the CVE, severity, and affected OpenHarmony versions provided. For more details, see the security bulletins released by third-parties.
CVE
severity
affected OpenHarmony versions
fix link
CVE-2022-1729
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/255>
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/299>
CVE-2022-29581
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/255>
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/299>
CVE-2022-20008
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/241>
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/214>
CVE-2022-1195
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/241>
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/214>
CVE-2022-1516
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/241>
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/214>
CVE-2022-30594
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/241>
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/214>
CVE-2022-1012
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/237>
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/224>
CVE-2022-29824
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x<https://gitee.com/openharmony/third_party_libxml2/pulls/23>
3.1.x<https://gitee.com/openharmony/third_party_libxml2/pulls/21>
CVE-2022-1475
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x<https://gitee.com/openharmony/third_party_ffmpeg/pulls/41>
3.1.x<https://gitee.com/openharmony/third_party_ffmpeg/pulls/36>
CVE-2022-27406
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
3.0.x<https://gitee.com/openharmony/third_party_freetype/pulls/17>
[3.1.x]not fixed
CVE-2022-27404
Critical
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
3.0.x<https://gitee.com/openharmony/third_party_freetype/pulls/17>
[3.1.x]not fixed
CVE-2022-1974
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/260>
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/302>
CVE-2022-1734
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
OpenHarmony-v3.1-Release
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/260>
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/214>
CVE-2022-1199
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/260>
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/333>
CVE-2022-1966
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/258>
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/332>
CVE-2022-1786
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.5-LTS
OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1-Release
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/258>
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/332>
CVE-2022-1280
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/233>
CVE-2022-45868
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/233>
1
0
2022年7月安全漏洞
发布于2022.7.5
漏洞编号
相关漏洞
漏洞描述
漏洞影响
受影响的版本
受影响的仓库
修复链接
参考链接
OpenHarmony-SA-2022-0701
NA
通信子系统蓝牙组件存在DoS漏洞,造成进程崩溃。
攻击者可在本地发起攻击,进入超大循环,导致进程崩溃。
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
communication_bluetooth
3.0.x<https://gitee.com/openharmony/communication_bluetooth/pulls/179>
本项目组上报
OpenHarmony-SA-2022-0702
NA
升级子系统升级包安装组件存在空指针引用,造成进程崩溃。
攻击者可在本地发起攻击,传入空指针,导致进程崩溃。
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
update_updater
3.0.x<https://gitee.com/openharmony/update_updater/pulls/101>
本项目组上报
OpenHarmony-SA-2022-0703
NA
通信子系统软总线存在校验绕过漏洞,可发起SA中继攻击。
攻击者可在本地发起攻击,造成权限绕过,可获取系统控制权。
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
communication_dsoftbus
3.0.x<https://gitee.com/openharmony/communication_dsoftbus/pulls/142>
本项目组上报
以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本,详细信息请参考三方公告。
CVE
严重程度
受影响的OpenHarmony版本
修复链接
CVE-2022-1292
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x<https://gitee.com/openharmony/third_party_openssl/pulls/48>
3.1.x<https://gitee.com/openharmony/third_party_openssl/pulls/49>
CVE-2022-27781
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
OpenHarmony-v1.1.0-Release到OpenHarmony-v1.1.4-LTS
3.0.x<https://gitee.com/openharmony/third_party_curl/pulls/63>
3.1.x<https://gitee.com/openharmony/third_party_curl/pulls/61>
1.1.x<https://gitee.com/openharmony/third_party_curl/pulls/60>
CVE-2022-27782
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
OpenHarmony-v1.1.0-Release到OpenHarmony-v1.1.4-LTS
3.0.x<https://gitee.com/openharmony/third_party_curl/pulls/63>
3.1.x<https://gitee.com/openharmony/third_party_curl/pulls/61>
1.1.x<https://gitee.com/openharmony/third_party_curl/pulls/60>
CVE-2022-0168
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/218>
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/214>
CVE-2022-0330
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/218>
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/214>
CVE-2022-0001
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/202>
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/214>
CVE-2022-0002
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/202>
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/214>
CVE-2022-23960
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/201>
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/214>
CVE-2022-0322
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/201>
CVE-2021-32078
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/198>
CVE-2021-38205
低
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/198>
CVE-2021-38166
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/198>
CVE-2021-42739
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/198>
CVE-2022-0854
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/194>
CVE-2022-23037
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/190>
CVE-2022-23039
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/190>
CVE-2022-23040
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/190>
CVE-2022-23038
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/190>
CVE-2022-23041
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/190>
CVE-2022-23042
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/190>
CVE-2022-23036
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/190>
CVE-2022-0998
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/181>
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/214>
CVE-2021-4203
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/180>
CVE-2021-39633
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/180>
CVE-2021-46283
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/180>
CVE-2021-4149
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/180>
CVE-2021-4204
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/163>
CVE-2021-3640
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/152>
CVE-2021-3669
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/152>
CVE-2021-3759
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/152>
CVE-2021-3752
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/152>
CVE-2020-27820
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/152>
CVE-2021-43976
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/152>
CVE-2021-43975
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/152>
CVE-2021-4001
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/152>
CVE-2021-4002
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/152>
CVE-2021-4037
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/152>
CVE-2020-12363
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/152>
CVE-2020-12364
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/152>
CVE-2021-39685
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/144>
CVE-2021-4083
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/144>
CVE-2021-45095
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/144>
CVE-2021-44733
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/144>
CVE-2021-45469
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/144>
CVE-2021-4197
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/144>
CVE-2021-45480
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/144>
CVE-2021-4155
低
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/144>
CVE-2021-4202
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/144>
Security Vulnerabilities in July 2022
published July 5,2022
Vulnerability ID
related Vulnerability
Vulnerability Descripton
Vulnerability Impact
affected versions
affected projects
fix link
reference
OpenHarmony-SA-2022-0701
NA
The bluetooth in communication subsystem has a DoS vulnerability.
Local attackers can trigger a large loop and crash the process.
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
communication_bluetooth
3.0.x<https://gitee.com/openharmony/communication_bluetooth/pulls/179>
Reported by OpenHarmony Team
OpenHarmony-SA-2022-0702
NA
The updater in update subsystem has a null pointer reference vulnerability.
Local attackers can input a nullptr and crash the process.
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
update_updater
3.0.x<https://gitee.com/openharmony/update_updater/pulls/101>
Reported by OpenHarmony Team
OpenHarmony-SA-2022-0703
NA
The dsoftbus in communication subsystem has an authentication bypass vulnerability which allows an "SA relay attack".
Local attackers can bypass authentication and get system control.
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
communication_dsoftbus
3.0.x<https://gitee.com/openharmony/communication_dsoftbus/pulls/142>
Reported by OpenHarmony Team
The following table lists the third-party library vulnerabilities with only the CVE, severity, and affected OpenHarmony versions provided. For more details, see the security bulletins released by third-parties.
CVE
severity
affected OpenHarmony versions
fix link
CVE-2022-1292
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x<https://gitee.com/openharmony/third_party_openssl/pulls/48>
3.1.x<https://gitee.com/openharmony/third_party_openssl/pulls/49>
CVE-2022-27781
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
OpenHarmony-v1.1.0-Release through OpenHarmony-v1.1.4-LTS
3.0.x<https://gitee.com/openharmony/third_party_curl/pulls/63>
3.1.x<https://gitee.com/openharmony/third_party_curl/pulls/61>
1.1.x<https://gitee.com/openharmony/third_party_curl/pulls/60>
CVE-2022-27782
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
OpenHarmony-v1.1.0-Release through OpenHarmony-v1.1.4-LTS
3.0.x<https://gitee.com/openharmony/third_party_curl/pulls/63>
3.1.x<https://gitee.com/openharmony/third_party_curl/pulls/61>
1.1.x<https://gitee.com/openharmony/third_party_curl/pulls/60>
CVE-2022-0168
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/218>
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/214>
CVE-2022-0330
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/218>
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/214>
CVE-2022-0001
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/202>
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/214>
CVE-2022-0002
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/202>
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/214>
CVE-2022-23960
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/201>
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/214>
CVE-2022-0322
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/201>
CVE-2021-32078
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/198>
CVE-2021-38205
Low
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/198>
CVE-2021-38166
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/198>
CVE-2021-42739
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/198>
CVE-2022-0854
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/194>
CVE-2022-23037
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/190>
CVE-2022-23039
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/190>
CVE-2022-23040
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/190>
CVE-2022-23038
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/190>
CVE-2022-23041
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/190>
CVE-2022-23042
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/190>
CVE-2022-23036
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/190>
CVE-2022-0998
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/181>
3.1.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/214>
CVE-2021-4203
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/180>
CVE-2021-39633
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/180>
CVE-2021-46283
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/180>
CVE-2021-4149
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/180>
CVE-2021-4204
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/163>
CVE-2021-3640
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/152>
CVE-2021-3669
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/152>
CVE-2021-3759
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/152>
CVE-2021-3752
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/152>
CVE-2020-27820
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/152>
CVE-2021-43976
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/152>
CVE-2021-43975
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/152>
CVE-2021-4001
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/152>
CVE-2021-4002
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/152>
CVE-2021-4037
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/152>
CVE-2020-12363
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/152>
CVE-2020-12364
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/152>
CVE-2021-39685
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/144>
CVE-2021-4083
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/144>
CVE-2021-45095
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/144>
CVE-2021-44733
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/144>
CVE-2021-45469
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/144>
CVE-2021-4197
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/144>
CVE-2021-45480
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/144>
CVE-2021-4155
Low
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/144>
CVE-2021-4202
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
3.0.x<https://gitee.com/openharmony/kernel_linux_5.10/pulls/144>
1
0
2022年6月安全漏洞
发布于2022.6.6
漏洞编号
相关漏洞
漏洞描述
漏洞影响
受影响的版本
受影响的仓库
修复链接
参考链接
OpenHarmony-SA-2022-0601
NA
事件通知子系统反序列化对象时会绕过认证机制。
攻击者可在本地发起攻击,造成权限绕过,导致服务端进程崩溃。
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS和OpenHarmony-v3.1-Release
notification_ces_standard
链接<https://gitee.com/openharmony/notification_common_event_service/pulls/269>
本项目组上报
OpenHarmony-SA-2022-0602
NA
事件通知子系统存在校验绕过漏洞,可发起SA中继攻击。
攻击者可在本地发起攻击,造成校验绕过,获得系统控制权。
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
notification_ces_standard
链接<https://gitee.com/openharmony/notification_common_event_service/pulls/245>
本项目组上报
OpenHarmony-SA-2022-0603
NA
升级服务组件存在校验绕过漏洞,可发起SA中继攻击。
攻击者可在本地发起攻击,造成校验绕过,获得系统控制权。
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
update_updateservice
链接<https://gitee.com/openharmony/update_updateservice/pulls/115>
本项目组上报
OpenHarmony-SA-2022-0604
NA
多媒体子系统存在校验绕过漏洞,可发起SA中继攻击。
攻击者可在本地发起攻击,造成校验绕过,获取系统控制权。
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
multimedia_media_standard
链接<https://gitee.com/openharmony/multimedia_media_standard/pulls/567>
本项目组上报
以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本,详细信息请参考三方公告。
CVE
严重程度
受影响的OpenHarmony版本
修复链接
CVE-2022-25313
中
OpenHarmony-v3.0-LTS和OpenHarmony-v3.0.1-LTS
链接<https://gitee.com/openharmony/third_party_expat/pulls/10>
CVE-2022-25314
高
OpenHarmony-v3.0-LTS和OpenHarmony-v3.0.1-LTS
链接<https://gitee.com/openharmony/third_party_expat/pulls/10>
CVE-2022-25315
中
OpenHarmony-v3.0-LTS和OpenHarmony-v3.0.1-LTS
链接<https://gitee.com/openharmony/third_party_expat/pulls/10>
CVE-2022-25235
高
OpenHarmony-v3.0-LTS和OpenHarmony-v3.0.1-LTS
链接<https://gitee.com/openharmony/third_party_expat/pulls/10>
CVE-2022-25236
严重
OpenHarmony-v3.0-LTS和OpenHarmony-v3.0.1-LTS
链接<https://gitee.com/openharmony/third_party_expat/pulls/10>
CVE-2022-23308
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.2-LTS
链接<https://gitee.com/openharmony/third_party_libxml2/pulls/11>
CVE-2022-25375
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
链接<https://gitee.com/openharmony/kernel_linux_5.10/pulls/146>
CVE-2022-25258
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
链接<https://gitee.com/openharmony/kernel_linux_5.10/pulls/146>
CVE-2022-0435
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
链接<https://gitee.com/openharmony/kernel_linux_5.10/pulls/146>
CVE-2022-24959
低
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
链接<https://gitee.com/openharmony/kernel_linux_5.10/pulls/146>
CVE-2021-44879
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
链接<https://gitee.com/openharmony/kernel_linux_5.10/pulls/146>
CVE-2022-24958
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
链接<https://gitee.com/openharmony/kernel_linux_5.10/pulls/146>
CVE-2021-45402
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
链接<https://gitee.com/openharmony/kernel_linux_5.10/pulls/146>
CVE-2021-4160
中
OpenHarmony-v3.0-LTS和OpenHarmony-v3.0.1-LTS
链接<https://gitee.com/openharmony/third_party_openssl/pulls/29>
CVE-2022-0778
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
链接<https://gitee.com/openharmony/third_party_openssl/pulls/34>
CVE-2022-0886
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
链接<https://gitee.com/openharmony/kernel_linux_5.10/pulls/143>
CVE-2022-1055
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS和OpenHarmony-v3.1-Release
链接<https://gitee.com/openharmony/kernel_linux_5.10/pulls/175>
CVE-2022-0995
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS和OpenHarmony-v3.1-Release
链接<https://gitee.com/openharmony/kernel_linux_5.10/pulls/175>
CVE-2021-39698
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS和OpenHarmony-v3.1-Release
链接<https://gitee.com/openharmony/kernel_linux_5.10/pulls/175>
CVE-2022-0494
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS和OpenHarmony-v3.1-Release
链接<https://gitee.com/openharmony/kernel_linux_5.10/pulls/175>
CVE-2022-1048
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS和OpenHarmony-v3.1-Release
链接<https://gitee.com/openharmony/kernel_linux_5.10/pulls/175>
CVE-2022-1016
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS和OpenHarmony-v3.1-Release
链接<https://gitee.com/openharmony/kernel_linux_5.10/pulls/175>
CVE-2021-39686
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS和OpenHarmony-v3.1-Release
链接<https://gitee.com/openharmony/kernel_linux_5.10/pulls/175>
CVE-2022-0500
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
链接<https://gitee.com/openharmony/kernel_linux_5.10/pulls/163>
CVE-2022-28390
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS和OpenHarmony-v3.1-Release
链接<https://gitee.com/openharmony/kernel_linux_5.10/pulls/181>
CVE-2022-28389
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS和OpenHarmony-v3.1-Release
链接<https://gitee.com/openharmony/kernel_linux_5.10/pulls/181>
CVE-2022-28388
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS和OpenHarmony-v3.1-Release
链接<https://gitee.com/openharmony/kernel_linux_5.10/pulls/181>
CVE-2022-28893
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS和OpenHarmony-v3.1-Release
链接<https://gitee.com/openharmony/kernel_linux_5.10/pulls/181>
CVE-2022-1353
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS和OpenHarmony-v3.1-Release
链接<https://gitee.com/openharmony/kernel_linux_5.10/pulls/181>
CVE-2022-29156
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS和OpenHarmony-v3.1-Release
链接<https://gitee.com/openharmony/kernel_linux_5.10/pulls/181>
CVE-2022-29156
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS和OpenHarmony-v3.1-Release
链接<https://gitee.com/openharmony/kernel_linux_5.10/pulls/181>
CVE-2022-28356
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS和OpenHarmony-v3.1-Release
链接<https://gitee.com/openharmony/kernel_linux_5.10/pulls/181>
CVE-2019-16089
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
链接<https://gitee.com/openharmony/kernel_linux_5.10/pulls/152>
CVE-2021-4156
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS和OpenHarmony-v3.1-Release
链接<https://gitee.com/openharmony/third_party_libsnd/pulls/10>
CVE-2022-22576
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS和OpenHarmony-v3.1-Release
链接<https://gitee.com/openharmony/third_party_curl/pulls/52>
CVE-2022-27775
低
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS和OpenHarmony-v3.1-Release
链接<https://gitee.com/openharmony/third_party_curl/pulls/52>
CVE-2022-27776
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS和OpenHarmony-v3.1-Release
链接<https://gitee.com/openharmony/third_party_curl/pulls/52>
CVE-2022-27774
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS和OpenHarmony-v3.1-Release
链接<https://gitee.com/openharmony/third_party_curl/pulls/52>
CVE-2021-3520
严重
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.2-LTS
链接<https://gitee.com/openharmony/third_party_lz4/pulls/2>
CVE-2021-44732
严重
OpenHarmony-v3.0-LTS和OpenHarmony-v3.0.1-LTS
链接<https://gitee.com/openharmony/third_party_mbedtls/pulls/31>
CVE-2021-36690
高
OpenHarmony-v3.0-LTS和OpenHarmony-v3.0.1-LTS
链接<https://gitee.com/openharmony/third_party_sqlite/pulls/4>
CVE-2021-3732
低
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
链接<https://gitee.com/openharmony/kernel_linux_5.10/pulls/180>
CVE-2021-22570
高
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.2-LTS
链接<https://gitee.com/openharmony/third_party_protobuf/pulls/26>
CVE-2021-22569
中
OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.2-LTS
链接<https://gitee.com/openharmony/third_party_protobuf/pulls/27>
Security Vulnerabilities in June 2022
published June 6,2022
Vulnerability ID
related Vulnerability
Vulnerability Descripton
Vulnerability Impact
affected versions
affected projects
fix link
reference
OpenHarmony-SA-2022-0601
NA
The notification subsystem in OpenHarmony has an authentication bypass vulnerability when deserialize an object.
Local attackers can bypass authenication and crash the server process.
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS and OpenHarmony-v3.1-Release
notification_ces_standard
Link<https://gitee.com/openharmony/notification_common_event_service/pulls/269>
Reported by OpenHarmony Team
OpenHarmony-SA-2022-0602
NA
The notification subsystem in OpenHarmony has an authentication bypass vulnerability which allows an "SA relay attack".
Local attackers can bypass authentication and get system control.
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
notification_ces_standard
Link<https://gitee.com/openharmony/notification_common_event_service/pulls/245>
Reported by OpenHarmony Team
OpenHarmony-SA-2022-0603
NA
The updateservice in OpenHarmony has an authentication bypass vulnerability which allows an "SA relay attack".
Local attackers can bypass authentication and get system control.
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
update_updateservice
Link<https://gitee.com/openharmony/update_updateservice/pulls/115>
Reported by OpenHarmony Team
OpenHarmony-SA-2022-0604
NA
The multimedia subsystem in OpenHarmony has an authentication bypass vulnerability which allows an "SA relay attack".
Local attackers can bypass authentication and get system control.
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
multimedia_media_standard
Link<https://gitee.com/openharmony/multimedia_media_standard/pulls/567>
Reported by OpenHarmony Team
The following table lists the third-party library vulnerabilities with only the CVE, severity, and affected OpenHarmony versions provided. For more details, see the security bulletins released by third-parties.
CVE
severity
affected OpenHarmony versions
fix link
CVE-2022-25313
Medium
OpenHarmony-v3.0-LTS and OpenHarmony-v3.0.1-LTS
Link<https://gitee.com/openharmony/third_party_expat/pulls/10>
CVE-2022-25314
High
OpenHarmony-v3.0-LTS and OpenHarmony-v3.0.1-LTS
Link<https://gitee.com/openharmony/third_party_expat/pulls/10>
CVE-2022-25315
Medium
OpenHarmony-v3.0-LTS and OpenHarmony-v3.0.1-LTS
Link<https://gitee.com/openharmony/third_party_expat/pulls/10>
CVE-2022-25235
High
OpenHarmony-v3.0-LTS and OpenHarmony-v3.0.1-LTS
Link<https://gitee.com/openharmony/third_party_expat/pulls/10>
CVE-2022-25236
Critical
OpenHarmony-v3.0-LTS and OpenHarmony-v3.0.1-LTS
Link<https://gitee.com/openharmony/third_party_expat/pulls/10>
CVE-2022-23308
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.2-LTS
Link<https://gitee.com/openharmony/third_party_libxml2/pulls/11>
CVE-2022-25375
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
Link<https://gitee.com/openharmony/kernel_linux_5.10/pulls/146>
CVE-2022-25258
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
Link<https://gitee.com/openharmony/kernel_linux_5.10/pulls/146>
CVE-2022-0435
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
Link<https://gitee.com/openharmony/kernel_linux_5.10/pulls/146>
CVE-2022-24959
Low
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
Link<https://gitee.com/openharmony/kernel_linux_5.10/pulls/146>
CVE-2021-44879
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
Link<https://gitee.com/openharmony/kernel_linux_5.10/pulls/146>
CVE-2022-24958
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
Link<https://gitee.com/openharmony/kernel_linux_5.10/pulls/146>
CVE-2021-45402
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
Link<https://gitee.com/openharmony/kernel_linux_5.10/pulls/146>
CVE-2021-4160
Medium
OpenHarmony-v3.0-LTS and OpenHarmony-v3.0.1-LTS
Link<https://gitee.com/openharmony/third_party_openssl/pulls/29>
CVE-2022-0778
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
Link<https://gitee.com/openharmony/third_party_openssl/pulls/34>
CVE-2022-0886
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
Link<https://gitee.com/openharmony/kernel_linux_5.10/pulls/143>
CVE-2022-1055
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS and OpenHarmony-v3.1-Release
Link<https://gitee.com/openharmony/kernel_linux_5.10/pulls/175>
CVE-2022-0995
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS and OpenHarmony-v3.1-Release
Link<https://gitee.com/openharmony/kernel_linux_5.10/pulls/175>
CVE-2021-39698
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS and OpenHarmony-v3.1-Release
Link<https://gitee.com/openharmony/kernel_linux_5.10/pulls/175>
CVE-2022-0494
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS and OpenHarmony-v3.1-Release
Link<https://gitee.com/openharmony/kernel_linux_5.10/pulls/175>
CVE-2022-1048
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS and OpenHarmony-v3.1-Release
Link<https://gitee.com/openharmony/kernel_linux_5.10/pulls/175>
CVE-2022-1016
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS and OpenHarmony-v3.1-Release
Link<https://gitee.com/openharmony/kernel_linux_5.10/pulls/175>
CVE-2021-39686
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS and OpenHarmony-v3.1-Release
Link<https://gitee.com/openharmony/kernel_linux_5.10/pulls/175>
CVE-2022-0500
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
Link<https://gitee.com/openharmony/kernel_linux_5.10/pulls/163>
CVE-2022-28390
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS and OpenHarmony-v3.1-Release
Link<https://gitee.com/openharmony/kernel_linux_5.10/pulls/181>
CVE-2022-28389
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS and OpenHarmony-v3.1-Release
Link<https://gitee.com/openharmony/kernel_linux_5.10/pulls/181>
CVE-2022-28388
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS and OpenHarmony-v3.1-Release
Link<https://gitee.com/openharmony/kernel_linux_5.10/pulls/181>
CVE-2022-28893
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS and OpenHarmony-v3.1-Release
Link<https://gitee.com/openharmony/kernel_linux_5.10/pulls/181>
CVE-2022-1353
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS and OpenHarmony-v3.1-Release
Link<https://gitee.com/openharmony/kernel_linux_5.10/pulls/181>
CVE-2022-29156
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS and OpenHarmony-v3.1-Release
Link<https://gitee.com/openharmony/kernel_linux_5.10/pulls/181>
CVE-2022-28356
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS and OpenHarmony-v3.1-Release
Link<https://gitee.com/openharmony/kernel_linux_5.10/pulls/181>
CVE-2019-16089
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
Link<https://gitee.com/openharmony/kernel_linux_5.10/pulls/152>
CVE-2021-4156
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS and OpenHarmony-v3.1-Release
Link<https://gitee.com/openharmony/third_party_libsnd/pulls/10>
CVE-2022-22576
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS and OpenHarmony-v3.1-Release
Link<https://gitee.com/openharmony/third_party_curl/pulls/52>
CVE-2022-27775
Low
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS and OpenHarmony-v3.1-Release
Link<https://gitee.com/openharmony/third_party_curl/pulls/52>
CVE-2022-27776
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS and OpenHarmony-v3.1-Release
Link<https://gitee.com/openharmony/third_party_curl/pulls/52>
CVE-2022-27774
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS and OpenHarmony-v3.1-Release
Link<https://gitee.com/openharmony/third_party_curl/pulls/52>
CVE-2021-3520
Critical
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.2-LTS
Link<https://gitee.com/openharmony/third_party_lz4/pulls/2>
CVE-2021-44732
Critical
OpenHarmony-v3.0-LTS and OpenHarmony-v3.0.1-LTS
Link<https://gitee.com/openharmony/third_party_mbedtls/pulls/31>
CVE-2021-36690
High
OpenHarmony-v3.0-LTS and OpenHarmony-v3.0.1-LTS
Link<https://gitee.com/openharmony/third_party_sqlite/pulls/4>
CVE-2021-3732
Low
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
Link<https://gitee.com/openharmony/kernel_linux_5.10/pulls/180>
CVE-2021-22570
High
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.2-LTS
Link<https://gitee.com/openharmony/third_party_protobuf/pulls/26>
CVE-2021-22569
Medium
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.2-LTS
Link<https://gitee.com/openharmony/third_party_protobuf/pulls/27>
1
0
2022年5月安全漏洞
发布于2022.5.6
漏洞编号
相关漏洞
漏洞描述
漏洞影响
受影响的版本
受影响的仓库
修复链接
参考链接
OpenHarmony-SA-2022-0501
NA
软总线子系统存在堆溢出漏洞。
攻击者可在本地发起攻击,造成内存访问越界,可获取系统控制权。
OpenHarmony-3.0-LTS
communication_dsoftbus
链接<https://gitee.com/openharmony/communication_dsoftbus/pulls/1198>
本项目组上报
OpenHarmony-SA-2022-0502
NA
软总线子系统在接收TCP消息时存在堆溢出漏洞。
攻击者可在局域网内发起攻击,进行远程代码执行,获得系统控制权。
OpenHarmony-3.0-LTS
communication_dsoftbus
链接<https://gitee.com/openharmony/communication_dsoftbus/pulls/1113>
本项目组上报
OpenHarmony-SA-2022-0503
NA
软总线处理设备同步消息时存在越界访问漏洞。
攻击者可在局域网内发起攻击,可造成内存访问越界,造成DoS攻击。
OpenHarmony-3.0-LTS
communication_dsoftbus
链接<https://gitee.com/openharmony/communication_dsoftbus/pulls/1369>
本项目组上报
OpenHarmony-SA-2022-0504
NA
Lock类包含的一个指针成员存在重复释放问题。
攻击者可在本地发起攻击,可获取系统控制权。
OpenHarmony-3.0-LTS
global_resmgr_standard
链接<https://gitee.com/openharmony/global_resmgr_standard/pulls/136>
本项目组上报
以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本,详细信息请参考三方公告。
CVE
严重程度
受影响的OpenHarmony版本
修复链接
CVE-2022-0778
中
OpenHarmony-3.0-LTS
链接<https://gitee.com/openharmony/third_party_openssl/pulls/34>
CVE-2018-25032
高
OpenHarmony-1.0-LTS
OpenHarmony-3.0-LTS
链接<https://gitee.com/openharmony/third_party_zlib/pulls/31>
链接<https://gitee.com/openharmony/third_party_zlib/pulls/30>
CVE-2021-28714
中
OpenHarmony-3.0-LTS
链接<https://gitee.com/openharmony/kernel_linux_5.10/commit/06639c05f98d596690a9…>
CVE-2021-28715
中
OpenHarmony-3.0-LTS
链接<https://gitee.com/openharmony/kernel_linux_5.10/commit/2938e8ac18d248567afe…>
CVE-2022-23222
高
OpenHarmony-3.0-LTS
链接<https://gitee.com/openharmony/kernel_linux_5.10/commit/4e695c44106d3f0f9908…>
CVE-2022-0185
高
OpenHarmony-3.0-LTS
链接<https://gitee.com/openharmony/kernel_linux_5.10/commit/76a954013f985828558d…>
CVE-2021-22600
高
OpenHarmony-3.0-LTS
链接<https://gitee.com/openharmony/kernel_linux_5.10/commit/214329f8032e15f72d39…>
CVE-2022-22942
高
OpenHarmony-3.0-LTS
链接<https://gitee.com/openharmony/kernel_linux_5.10/commit/9a967f71164cf3b3fc78…>
CVE-2022-0492
高
OpenHarmony-3.0-LTS
链接<https://gitee.com/openharmony/kernel_linux_5.10/commit/ea8f5c0c115c8c61a76b…>
CVE-2022-24448
低
OpenHarmony-3.0-LTS
链接<https://gitee.com/openharmony/kernel_linux_5.10/commit/9e4a6ed92bb4e0b964c5…>
链接<https://gitee.com/openharmony/kernel_linux_5.10/commit/af9e3d1a2dc61aa346e3…>
链接<https://gitee.com/openharmony/kernel_linux_5.10/commit/51fef9de52b5b1431cac…>
CVE-2022-0516
高
OpenHarmony-3.0-LTS
链接<https://gitee.com/openharmony/kernel_linux_5.10/commit/8ba71b83e7acfbbf351d…>
CVE-2022-0617
中
OpenHarmony-3.0-LTS
链接<https://gitee.com/openharmony/kernel_linux_5.10/commit/999c29733c45ac8864c6…>
链接<https://gitee.com/openharmony/kernel_linux_5.10/commit/7d65b9dbe4277bac42eb…>
CVE-2022-0847
高
OpenHarmony-3.0-LTS
链接<https://gitee.com/openharmony/kernel_linux_5.10/commit/b4e786c8ebae053b2158…>
CVE-2022-26490
高
OpenHarmony-3.0-LTS
链接<https://gitee.com/openharmony/kernel_linux_5.10/pulls/141>
CVE-2022-25636
高
OpenHarmony-3.0-LTS
链接<https://gitee.com/openharmony/kernel_linux_5.10/commit/62e62125967779009361…>
CVE-2022-26966
中
OpenHarmony-3.0-LTS
链接<https://gitee.com/openharmony/kernel_linux_5.10/commit/4b80b2d8eba4d9df430b…>
CVE-2022-1011
高
OpenHarmony-3.0-LTS
链接<https://gitee.com/openharmony/kernel_linux_5.10/commit/013bad7096d7bee6a3be…>
CVE-2022-27223
高
OpenHarmony-3.0-LTS
链接<https://gitee.com/openharmony/kernel_linux_5.10/commit/5939446d63ddecefdbe3…>
Security Vulnerabilities in May 2022
published May 6,2022
Vulnerability ID
related Vulnerability
Vulnerability Descripton
Vulnerability Impact
affected versions
affected projects
fix link
reference
OpenHarmony-SA-2022-0501
NA
The softbus subsystem in OpenHarmony has a heap overflow vulnerability.
Local attackers can overwrite the memory and get system control.
OpenHarmony-3.0-LTS
communication_dsoftbus
Link<https://gitee.com/openharmony/communication_dsoftbus/pulls/1198>
Reported by OpenHarmony Team
OpenHarmony-SA-2022-0502
NA
The softbus subsystem in OpenHarmony has a heap overflow vulnerability when receive a tcp message.
LAN attackers can lead to remote code execution(RCE) and get system control.
OpenHarmony-3.0-LTS
communication_dsoftbus
Link<https://gitee.com/openharmony/communication_dsoftbus/pulls/1113>
Reported by OpenHarmony Team
OpenHarmony-SA-2022-0503
NA
The softbus subsystem in OpenHarmony has an out-of-bounds access vulnerability when handle a synchronized message from another device.
Local attackers can elevate permissions to SYSTEM.
OpenHarmony-3.0-LTS
communication_dsoftbus
Link<https://gitee.com/openharmony/communication_dsoftbus/pulls/1369>
Reported by OpenHarmony Team
OpenHarmony-SA-2022-0504
NA
The calss Lock in OpenHarmony has a double free vulnerability.
Local attackers can elevate permissions to SYSTEM.
OpenHarmony-3.0-LTS
global_resmgr_standard
Link<https://gitee.com/openharmony/global_resmgr_standard/pulls/136>
Reported by OpenHarmony Team
The following table lists the third-party library vulnerabilities with only the CVE, severity, and affected OpenHarmony versions provided. For more details, see the security bulletins released by third-parties.
CVE
severity
affected OpenHarmony versions
fix link
CVE-2022-0778
Medium
OpenHarmony-3.0-LTS
Link<https://gitee.com/openharmony/third_party_openssl/pulls/34>
CVE-2018-25032
High
OpenHarmony-1.0-LTS
OpenHarmony-3.0-LTS
Link<https://gitee.com/openharmony/third_party_zlib/pulls/31>
Link<https://gitee.com/openharmony/third_party_zlib/pulls/30>
CVE-2021-28714
Medium
OpenHarmony-3.0-LTS
Link<https://gitee.com/openharmony/kernel_linux_5.10/commit/06639c05f98d596690a9…>
CVE-2021-28715
Medium
OpenHarmony-3.0-LTS
Link<https://gitee.com/openharmony/kernel_linux_5.10/commit/2938e8ac18d248567afe…>
CVE-2022-23222
High
OpenHarmony-3.0-LTS
Link<https://gitee.com/openharmony/kernel_linux_5.10/commit/4e695c44106d3f0f9908…>
CVE-2022-0185
High
OpenHarmony-3.0-LTS
Link<https://gitee.com/openharmony/kernel_linux_5.10/commit/76a954013f985828558d…>
CVE-2021-22600
High
OpenHarmony-3.0-LTS
Link<https://gitee.com/openharmony/kernel_linux_5.10/commit/214329f8032e15f72d39…>
CVE-2022-22942
High
OpenHarmony-3.0-LTS
Link<https://gitee.com/openharmony/kernel_linux_5.10/commit/9a967f71164cf3b3fc78…>
CVE-2022-0492
High
OpenHarmony-3.0-LTS
Link<https://gitee.com/openharmony/kernel_linux_5.10/commit/ea8f5c0c115c8c61a76b…>
CVE-2022-24448
Low
OpenHarmony-3.0-LTS
Link<https://gitee.com/openharmony/kernel_linux_5.10/commit/9e4a6ed92bb4e0b964c5…>
Link<https://gitee.com/openharmony/kernel_linux_5.10/commit/af9e3d1a2dc61aa346e3…>
Link<https://gitee.com/openharmony/kernel_linux_5.10/commit/51fef9de52b5b1431cac…>
CVE-2022-0516
High
OpenHarmony-3.0-LTS
Link<https://gitee.com/openharmony/kernel_linux_5.10/commit/8ba71b83e7acfbbf351d…>
CVE-2022-0617
Medium
OpenHarmony-3.0-LTS
Link<https://gitee.com/openharmony/kernel_linux_5.10/commit/999c29733c45ac8864c6…>
Link<https://gitee.com/openharmony/kernel_linux_5.10/commit/7d65b9dbe4277bac42eb…>
CVE-2022-0847
High
OpenHarmony-3.0-LTS
Link<https://gitee.com/openharmony/kernel_linux_5.10/commit/b4e786c8ebae053b2158…>
CVE-2022-26490
High
OpenHarmony-3.0-LTS
Link<https://gitee.com/openharmony/kernel_linux_5.10/pulls/141>
CVE-2022-25636
High
OpenHarmony-3.0-LTS
Link<https://gitee.com/openharmony/kernel_linux_5.10/commit/62e62125967779009361…>
CVE-2022-26966
Medium
OpenHarmony-3.0-LTS
Link<https://gitee.com/openharmony/kernel_linux_5.10/commit/4b80b2d8eba4d9df430b…>
CVE-2022-1011
High
OpenHarmony-3.0-LTS
Link<https://gitee.com/openharmony/kernel_linux_5.10/commit/013bad7096d7bee6a3be…>
CVE-2022-27223
High
OpenHarmony-3.0-LTS
Link<https://gitee.com/openharmony/kernel_linux_5.10/commit/5939446d63ddecefdbe3…>
1
0