发布于2025.02.11

备注:OpenHarmony 5.0阶段各分支中当前仅对OpenHarmony-5.0.2-Release分支进行安全漏洞维护。

CVE漏洞描述漏洞影响CVSS3.1基础得分受影响的版本受影响的仓库修复链接
CVE-2025-0302liteos_a内核整数溢出漏洞本地攻击者可通过本漏洞造成DOS5.5OpenHarmony-v4.1-Releasekernel_liteos_a4.1.x
CVE-2025-0303liteos_a内核堆栈溢出漏洞本地攻击者可通过本漏洞获取root权限8.8OpenHarmony-v4.1-Releasekernel_liteos_a4.1.x
CVE-2025-0304liteos_a内核UAF漏洞本地攻击者可通过本漏洞获取root权限8.8OpenHarmony-v4.1-Releasekernel_liteos_a4.1.x

以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本,详细信息请参考三方公告。

CVE严重程度CVSS 3.1得分受影响的仓库受影响的OpenHarmony版本修复链接
CVE-2024-53142低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-53140低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-53125低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-53124中危4.7kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-53079低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-53068低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-53066低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-53063低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-53058中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-53054中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50304低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50302中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50301低危2.6kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50290高危8.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50268低危3.5kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50262高危8.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50258中危4.8kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-50256中危4.8kernel_linux_5.10OpenHarmony-v4.1-Release OpenHarmony-v5.0.2-Release5.0.2.x 4.1.x
CVE-2024-50237中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50195中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50194中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50192中危4.6kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50191中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50150高危7.1kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50142中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50135中危4.6kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50099中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50089低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-50013中危5.7kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-49983高危8.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-49975中危5.7kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-49949中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-47660低危0.0kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-46826中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x
CVE-2024-42098中危5.5kernel_linux_5.10OpenHarmony-v4.1-Release4.1.x

以下是各维护版本的安全补丁标签,请在合入当月及之前全部对应安全补丁之后,更新安全补丁标签。

安全补丁标签链接
2025年02月[5.0.2.x]
[4.1.x]