发布于2025.03.04

备注:OpenHarmony 5.0阶段各分支中当前仅对OpenHarmony-5.0.2-Release分支进行安全漏洞维护。

CVE漏洞描述漏洞影响CVSS3.1基础得分受影响的版本受影响的仓库修复链接
CVE-2025-0587arkcompiler_ets_runtime整数溢出漏洞本地攻击者可在受限场景造成任意代码执行3.8OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x 4.1.x
CVE-2025-23234arkcompiler_ets_runtime栈溢出漏洞本地攻击者可造成DOS3.3OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x 4.1.x
CVE-2025-21098liteos_a内核存在的权限绕过漏洞本地攻击者可造成信息泄露5.5OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Releasekernel_liteos_a5.0.2.x 4.1.x
CVE-2025-20042liteos_a内核越界读漏洞本地攻击者可造成信息泄露5.5OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Releasekernel_liteos_a5.0.2.x 4.1.x
CVE-2025-22443arkcompiler_ets_runtime越界读漏洞本地攻击者可造成DOS3.3OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x 4.1.x
CVE-2025-20021arkcompiler_ets_runtime越界读漏洞本地攻击者可造成DOS3.3OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x
CVE-2025-21089arkcompiler_ets_runtime越界读漏洞本地攻击者可造成DOS3.3OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x
CVE-2025-22897arkcompiler_ets_runtime栈溢出漏洞本地攻击者可造成DOS3.3OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x
CVE-2025-23420arkcompiler_ets_runtime越界写漏洞本地攻击者可造成DOS3.8OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x
CVE-2025-22835arkcompiler_ets_runtime越界写漏洞本地攻击者可造成DOS3.8OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x 4.1.x
CVE-2025-21084arkcompiler_ets_runtime空指针解引用漏洞本地攻击者可造成DOS3.8OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x
CVE-2025-22847arkcompiler_ets_runtime越界读漏洞本地攻击者可造成DOS3.3OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x
CVE-2025-23418arkcompiler_ets_runtime越界读漏洞本地攻击者可造成DOS3.3OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x 4.1.x
CVE-2025-20024arkcompiler_ets_runtime整数溢出漏洞本地攻击者可在受限场景造成任意代码执行3.8OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x
CVE-2025-21097arkcompiler_ets_runtime空指针解引用漏洞本地攻击者可造成DOS3.3OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x
CVE-2025-20081communication_dsoftbus UAF漏洞本地攻击者可在受限场景造成任意代码执行3.8OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Releasecommunication_dsoftbus5.0.2.x 4.1.x
CVE-2025-23409communication_dsoftbus UAF漏洞本地攻击者可在受限场景造成任意代码执行3.8OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Releasecommunication_dsoftbus5.0.2.x 4.1.x
CVE-2025-20091communication_dsoftbus UAF漏洞本地攻击者可在受限场景造成任意代码执行3.8OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Releasecommunication_dsoftbus5.0.2.x 4.1.x
CVE-2025-24301arkcompiler_ets_runtime UAF漏洞本地攻击者可在受限场景造成任意代码执行3.8OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x
CVE-2025-24309arkcompiler_ets_runtime越界写漏洞本地攻击者可在受限场景造成任意代码执行3.8OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x
CVE-2025-23414arkcompiler_ets_runtime UAF漏洞本地攻击者可在受限场景造成任意代码执行3.8OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x
CVE-2025-23240arkcompiler_ets_runtime越界写漏洞本地攻击者可在受限场景造成任意代码执行3.8OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x 4.1.x
CVE-2025-22837arkcompiler_ets_runtime空指针解引用漏洞本地攻击者可造成DOS3.3OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x 4.1.x
CVE-2025-20011communication_dsoftbus内存泄露漏洞本地攻击者可造成DOS3.3OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Releasecommunication_dsoftbus5.0.2.x 4.1.x
CVE-2025-20626arkcompiler_ets_runtime UAF漏洞本地攻击者可在受限场景造成任意代码执行3.8OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x
CVE-2025-22841arkcompiler_ets_runtime越界读漏洞本地攻击者可造成DOS3.3OpenHarmony-v5.0.2-Releasearkcompiler_ets_runtime5.0.2.x

以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本,详细信息请参考三方公告。

CVE严重程度CVSS 3.1得分受影响的仓库受影响的OpenHarmony版本修复链接
CVE-2024-56756中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-56698中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-56670中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-56629中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-56616尚未提供kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-56615高危7.8kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-56587中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-56586尚未提供kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-56574中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-56569中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-53221中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-53218尚未提供kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-53147尚未提供kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-53144尚未提供kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-53104中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-53099低危3.5kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x

以下是各维护版本的安全补丁标签,请在合入当月及之前全部对应安全补丁之后,更新安全补丁标签。

安全补丁标签链接
2025年03月[5.0.2.x]
[4.1.x]