20227月安全漏洞

发布于2022.7.5

漏洞编号

相关漏洞

漏洞描述

漏洞影响

受影响的版本

受影响的仓库

修复链接

参考链接

OpenHarmony-SA-2022-0701

NA

通信子系统蓝牙组件存在DoS漏洞,造成进程崩溃。

攻击者可在本地发起攻击,进入超大循环,导致进程崩溃。

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

communication_bluetooth

3.0.x

本项目组上报

OpenHarmony-SA-2022-0702

NA

升级子系统升级包安装组件存在空指针引用,造成进程崩溃。

攻击者可在本地发起攻击,传入空指针,导致进程崩溃。

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

update_updater

3.0.x

本项目组上报

OpenHarmony-SA-2022-0703

NA

通信子系统软总线存在校验绕过漏洞,可发起SA中继攻击。

攻击者可在本地发起攻击,造成权限绕过,可获取系统控制权。

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

communication_dsoftbus

3.0.x

本项目组上报

以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本,详细信息请参考三方公告。

CVE

严重程度

受影响的OpenHarmony版本

修复链接

CVE-2022-1292

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release

3.0.x
3.1.x

CVE-2022-27781

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
OpenHarmony-v1.1.0-Release
OpenHarmony-v1.1.4-LTS

3.0.x
3.1.x
1.1.x

CVE-2022-27782

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
OpenHarmony-v1.1.0-Release
OpenHarmony-v1.1.4-LTS

3.0.x
3.1.x
1.1.x

CVE-2022-0168

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release

3.0.x
3.1.x

CVE-2022-0330

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release

3.0.x
3.1.x

CVE-2022-0001

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release

3.0.x
3.1.x

CVE-2022-0002

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release

3.0.x
3.1.x

CVE-2022-23960

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release

3.0.x
3.1.x

CVE-2022-0322

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-32078

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-38205

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-38166

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-42739

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

3.0.x

CVE-2022-0854

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

3.0.x

CVE-2022-23037

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

3.0.x

CVE-2022-23039

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

3.0.x

CVE-2022-23040

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

3.0.x

CVE-2022-23038

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

3.0.x

CVE-2022-23041

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

3.0.x

CVE-2022-23042

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

3.0.x

CVE-2022-23036

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

3.0.x

CVE-2022-0998

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release

3.0.x
3.1.x

CVE-2021-4203

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-39633

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-46283

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-4149

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-4204

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-3640

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-3669

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-3759

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-3752

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

3.0.x

CVE-2020-27820

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-43976

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-43975

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-4001

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-4002

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-4037

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

3.0.x

CVE-2020-12363

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

3.0.x

CVE-2020-12364

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-39685

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-4083

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-45095

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-44733

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-45469

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-4197

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-45480

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-4155

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-4202

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.3-LTS

3.0.x

 

 

Security Vulnerabilities in July 2022

published July 5,2022

Vulnerability ID

related Vulnerability

Vulnerability Descripton

Vulnerability Impact

affected versions

affected projects

fix link

reference

OpenHarmony-SA-2022-0701

NA

The bluetooth in communication subsystem has a DoS vulnerability.

Local attackers can trigger a large loop and crash the process.

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

communication_bluetooth

3.0.x

Reported by OpenHarmony Team

OpenHarmony-SA-2022-0702

NA

The updater in update subsystem has a null pointer reference vulnerability.

Local attackers can input a nullptr and crash the process.

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

update_updater

3.0.x

Reported by OpenHarmony Team

OpenHarmony-SA-2022-0703

NA

The dsoftbus in communication subsystem has an authentication bypass vulnerability which allows an "SA relay attack".

Local attackers can bypass authentication and get system control.

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

communication_dsoftbus

3.0.x

Reported by OpenHarmony Team

The following table lists the third-party library vulnerabilities with only the CVE, severity, and affected OpenHarmony versions provided. For more details, see the security bulletins released by third-parties.

CVE

severity

affected OpenHarmony versions

fix link

CVE-2022-1292

Medium

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release

3.0.x
3.1.x

CVE-2022-27781

Medium

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
OpenHarmony-v1.1.0-Release through OpenHarmony-v1.1.4-LTS

3.0.x
3.1.x
1.1.x

CVE-2022-27782

Medium

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
OpenHarmony-v1.1.0-Release through OpenHarmony-v1.1.4-LTS

3.0.x
3.1.x
1.1.x

CVE-2022-0168

Medium

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release

3.0.x
3.1.x

CVE-2022-0330

High

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release

3.0.x
3.1.x

CVE-2022-0001

Medium

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release

3.0.x
3.1.x

CVE-2022-0002

Medium

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release

3.0.x
3.1.x

CVE-2022-23960

Medium

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release

3.0.x
3.1.x

CVE-2022-0322

Medium

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-32078

High

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-38205

Low

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-38166

High

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-42739

Medium

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

3.0.x

CVE-2022-0854

Medium

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

3.0.x

CVE-2022-23037

High

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

3.0.x

CVE-2022-23039

High

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

3.0.x

CVE-2022-23040

High

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

3.0.x

CVE-2022-23038

High

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

3.0.x

CVE-2022-23041

High

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

3.0.x

CVE-2022-23042

High

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

3.0.x

CVE-2022-23036

High

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

3.0.x

CVE-2022-0998

High

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release

3.0.x
3.1.x

CVE-2021-4203

Medium

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-39633

Medium

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-46283

Medium

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-4149

Medium

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-4204

Medium

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-3640

Medium

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-3669

Medium

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-3759

Medium

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-3752

High

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

3.0.x

CVE-2020-27820

Medium

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-43976

Medium

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-43975

Medium

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-4001

Medium

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-4002

Medium

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-4037

Medium

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

3.0.x

CVE-2020-12363

Medium

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

3.0.x

CVE-2020-12364

Medium

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-39685

High

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-4083

High

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-45095

Medium

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-44733

High

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-45469

High

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-4197

Medium

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-45480

Medium

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-4155

Low

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

3.0.x

CVE-2021-4202

High

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.3-LTS

3.0.x