发布于2024.07.02

CVE漏洞描述漏洞影响严重 程度受影响的版本受影响的仓库修复链接
CVE-2024-31071方舟eTS运行时类型混淆漏洞本地攻击者通过本漏洞造成app crash低危OpenHarmony-v4.0-Releasarkcompiler_ets_runtime4.0.x
CVE-2024-37030方舟eTS运行时释放后使用漏洞远程攻击者通过本漏洞可在任意应用中执行代码高危OpenHarmony-v4.0-Releasarkcompiler_ets_frontend4.0.x
CVE-2024-36243方舟eTS运行时跨界内存读漏洞远程攻击者通过本漏洞可在任意应用中执行代码高危OpenHarmony-v4.0-Releasarkcompiler_ets_runtime4.0.x
CVE-2024-36278方舟eTS运行时类型混淆漏洞本地攻击者通过本漏洞造成app crash低危OpenHarmony-v4.0-Releasarkcompiler_ets_runtime4.0.x
CVE-2024-36260方舟eTS运行时跨界内存写漏洞远程攻击者通过本漏洞可在任意应用中执行代码高危OpenHarmony-v4.0-Releasarkcompiler_ets_runtime4.0.x
CVE-2024-37185方舟eTS运行时跨界内存写漏洞远程攻击者通过本漏洞可在任意应用中执行代码高危OpenHarmony-v4.0-Releasarkcompiler_ets_runtime4.0.x
CVE-2024-37077方舟eTS运行时跨界内存写漏洞远程攻击者通过本漏洞可在任意应用中执行代码高危OpenHarmony-v4.0-Releasarkcompiler_ets_runtime4.0.x

以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本

CVE严重程度CVSS 3.1 得分受影响的仓库受影响的OpenHarmony版本修复链接
CVE-2021-47474高危8.0kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2021-47479高危7.1kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2021-47483高危7.1kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2021-47485高危8.0kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2021-47506高危7.1kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2021-47521高危8.0kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2022-48655高危7.8kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2023-52467中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2024-26602中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2024-26852中危4.6kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-26862中危4.6kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2024-26883高危7.8kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-26884高危7.8kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-26885高危7.8kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-26901中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-26903中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-26923低危2.6kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-27004中危4.8kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-27038低危2.7kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-31755中危5.5third_party_cJSONOpenHarmony-v4.0-Release4.0.x

请在合入当月及之前全部已公开安全补丁之后,参考如下各维护版本的安全补丁标签更新方法,更新安全补丁标签至07月。

对应维护版本安全补丁修改方式参考链接
4.1.xhttps://gitee.com/openharmony/startup_init/pulls/2895
4.0.xhttps://gitee.com/openharmony/startup_init/pulls/2894