发布于2026.08.04

备注:OpenHarmony-5.0.3-Release分支当前已停止维护,后续这个分支的安全漏洞也不再维护,详情参见社区公告。

OpenHarmony-5.0.3-Release分支停止维护公告

CVE漏洞描述漏洞影响严重程度CVSS3.1基础得分受影响的版本受影响的仓库修复链接
CVE-2026-50001communication_bluetooth 权限绕过漏洞本地攻击者可造成DOS低危3.3OpenHarmony-v6.1-Releasecommunication_bluetooth6.1.x
CVE-2026-41955web_webview 越界读漏洞远程攻击者可造成DOS中危6.5OpenHarmony-v5.1.0-Release OpenHarmony-v6.0-Releaseweb_webview6.0.x 5.1.0.x
CVE-2026-50049arkcompiler_ets_runtime 越界写漏洞本地攻击者可造成任意代码执行中危5.5OpenHarmony-v6.0-Releasearkcompiler_ets_runtime6.0.x
CVE-2026-21395arkui_ace_engine 越界写漏洞本地攻击者可造成任意代码执行中危5.5OpenHarmony-v5.1.0-Releasearkui_ace_engine5.1.0.x
CVE-2026-49031kernel_liteos_a 越界写漏洞本地攻击者可造成任意代码执行高危7.8OpenHarmony-v5.1.0-Release OpenHarmony-v6.0-Release OpenHarmony-v6.1-Releasekernel_liteos_a6.0.x 5.1.0.x 6.1.x
CVE-2026-50051kernel_liteos_a 越界写漏洞本地攻击者可造成DOS低危3.3OpenHarmony-v5.1.0-Release OpenHarmony-v6.0-Release OpenHarmony-v6.1-Releasekernel_liteos_a6.0.x 5.1.0.x 6.1.x
CVE-2026-40625kernel_liteos_m 空指针解引用漏洞本地攻击者可造成任意代码执行中危6.0OpenHarmony-v5.1.0-Release OpenHarmony-v6.0-Release OpenHarmony-v6.1-Releasekernel_liteos_m6.0.x 5.1.0.x 6.1.x
CVE-2026-57888kernel_liteos_a 越界写漏洞本地攻击者可造成任意代码执行中危5.5OpenHarmony-v5.1.0-Release OpenHarmony-v6.0-Release OpenHarmony-v6.1-Releasekernel_liteos_a6.0.x 5.1.0.x 6.1.x
CVE-2026-59777kernel_liteos_a 不当输入验证漏洞本地攻击者可造成DOS低危3.3OpenHarmony-v5.1.0-Release OpenHarmony-v6.0-Release OpenHarmony-v6.1-Releasekernel_liteos_a6.0.x 5.1.0.x 6.1.x
CVE-2026-58516kernel_liteos_a 不当输入验证漏洞本地攻击者可造成任意代码执行高危7.1OpenHarmony-v5.1.0-Release OpenHarmony-v6.0-Release OpenHarmony-v6.1-Releasekernel_liteos_a6.0.x 5.1.0.x 6.1.x
CVE-2026-56753kernel_liteos_a 不当输入验证漏洞本地攻击者可造成DOS低危1.9OpenHarmony-v5.1.0-Release OpenHarmony-v6.0-Release OpenHarmony-v6.1-Releasekernel_liteos_a6.0.x 5.1.0.x 6.1.x
CVE-2026-59760multimedia_av_codec 不当输入验证漏洞本地攻击者可造成信息泄露中危4.3OpenHarmony-v6.0-Release OpenHarmony-v6.1-Releasemultimedia_av_codec6.0.x 6.1.x
CVE-2026-55989multimedia_audio_framework 空指针解引用漏洞本地攻击者可造成DOS低危3.3OpenHarmony-v6.1-Releasemultimedia_audio_framework6.1.x
CVE-2026-56656base_location 敏感信息泄露漏洞本地攻击者可造成信息泄露低危3.3OpenHarmony-v6.1-Releasebase_location6.1.x
CVE-2026-58313bundlemanager_app_domain_verify UAF漏洞本地攻击者可造成任意代码执行高危7.8OpenHarmony-v6.1-Releasebundlemanager_app_domain_verify6.1.x

以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本,详细信息请参考三方公告。

CVE严重程度CVSS 3.1得分受影响的仓库受影响的OpenHarmony版本修复链接
CVE-2026-40200高危8.1third_party_muslOpenHarmony-v6.0-Release OpenHarmony-v6.1-Release6.0.x 6.1.x
CVE-2025-71077尚未提供kernel_linux_6.6OpenHarmony-v6.0-Release OpenHarmony-v6.1-Release6.0.x 6.1.x
CVE-2025-68742尚未提供kernel_linux_6.6OpenHarmony-v6.0-Release OpenHarmony-v6.1-Release6.0.x 6.1.x
CVE-2025-68282尚未提供kernel_linux_6.6OpenHarmony-v6.0-Release OpenHarmony-v6.1-Release6.0.x 6.1.x
CVE-2025-62408中危5.9third_party_caresOpenHarmony-v6.1-Release6.1.x
CVE-2025-40164尚未提供kernel_linux_6.6OpenHarmony-v6.0-Release OpenHarmony-v6.1-Release6.0.x 6.1.x
CVE-2025-21691尚未提供kernel_linux_6.6OpenHarmony-v6.0-Release OpenHarmony-v6.1-Release6.0.x 6.1.x
CVE-2025-21665中危5.5kernel_linux_6.6OpenHarmony-v6.0-Release OpenHarmony-v6.1-Release6.0.x 6.1.x
CVE-2024-58078中危5.5kernel_linux_6.6OpenHarmony-v6.0-Release OpenHarmony-v6.1-Release6.0.x 6.1.x
CVE-2024-57951尚未提供kernel_linux_6.6OpenHarmony-v6.0-Release OpenHarmony-v6.1-Release6.0.x 6.1.x
CVE-2024-57930尚未提供kernel_linux_6.6OpenHarmony-v6.0-Release OpenHarmony-v6.1-Release6.0.x 6.1.x
CVE-2024-53206尚未提供kernel_linux_6.6OpenHarmony-v6.0-Release OpenHarmony-v6.1-Release6.0.x 6.1.x
CVE-2024-45002中危5.5kernel_linux_6.6OpenHarmony-v6.0-Release OpenHarmony-v6.1-Release6.0.x 6.1.x
CVE-2024-40908尚未提供kernel_linux_6.6OpenHarmony-v6.0-Release OpenHarmony-v6.1-Release6.0.x 6.1.x
CVE-2024-38620尚未提供kernel_linux_6.6OpenHarmony-v6.0-Release OpenHarmony-v6.1-Release6.0.x 6.1.x
CVE-2024-23848中危5.5kernel_linux_6.6OpenHarmony-v6.0-Release OpenHarmony-v6.1-Release6.0.x 6.1.x

以下是各维护版本的安全补丁标签,请在合入当月及之前全部对应安全补丁之后,更新安全补丁标签。

对应维护版本安全补丁修改方式参考链接
6.1.xhttps://gitcode.com/openharmony/startup_init/pull/4767
6.0.xhttps://gitcode.com/openharmony/startup_init/pull/4766
5.1.0.xhttps://gitcode.com/openharmony/startup_init/pull/4765