202210月安全漏洞

发布于2022.10.11
最后更新于2022.10.11

漏洞编号

相关漏洞

漏洞描述

漏洞影响

CVSS3.1基础得分

受影响的版本

受影响的仓库

修复链接

参考链接

OpenHarmony-SA-2022-1001

CVE-2022-42488

启动子系统param服务缺少权限校验。

攻击者可在本地发起攻击,获取root权限,关闭安全特性或对任意服务造成DoS攻击。

8.4

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release

startup_init_lite

3.1.x
3.1.x

本项目组上报

OpenHarmony-SA-2022-1002

CVE-2022-42464

dev/mmz_userdev驱动存在内核内存非法映射漏洞。

攻击者可在本地发起攻击,非法映射内存并进行读写,可提升到root权限或造成设备重启。利用此漏洞需要system UID

6.7

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.6-LTS

device_board_hisilicon
device_hisilicon_hi3516dv300

3.1.x
3.0.x

本项目组上报

OpenHarmony-SA-2022-1003

CVE-2022-41686

dev/mmz_userdev驱动存在越界读写漏洞。

攻击者可在本地发起攻击,越界读写内存地址,造成内存泄露或崩溃。利用此漏洞需要system UID

5.1

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.6-LTS

device_board_hisilicon
device_hisilicon_hispark_taurus

3.1.x
3.0.x

本项目组上报

OpenHarmony-SA-2022-1004

CVE-2022-42463

通信子系统softbus_server服务的一个回调处理函数存在无需认证和加密的漏洞。

攻击者可以在分布式网络发起攻击,发送蓝牙rfcomm报文到任意远程设备,执行任意命令。

8.3

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release

communication_dsoftbus

3.1.x

本项目组上报

以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本,详细信息请参考三方公告。

CVE

严重程度

受影响的OpenHarmony版本

修复链接

CVE-2022-27405

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.1-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.5-LTS
OpenHarmony-v1.1.0-release
OpenHarmony-v1.1.5-LTS

3.1.x
3.0.x
1.1.x

CVE-2022-2959

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.6-LTS

3.1.x
3.0.x

CVE-2022-2991

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.6-LTS

3.1.x
3.0.x

CVE-2022-2938

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.6-LTS

3.1.x
3.0.x

CVE-2022-2586

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.5-LTS

3.1.x
3.0.x

CVE-2022-2588

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.5-LTS

3.1.x
3.0.x

CVE-2022-2585

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.5-LTS

3.1.x
3.0.x

CVE-2022-2503

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.6-LTS

3.1.x
3.0.x

CVE-2022-20369

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.5-LTS

3.1.x
3.0.x

CVE-2022-20368

严重

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.5-LTS

3.1.x
3.0.x

CVE-2022-2639

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.5-LTS

3.1.x
3.0.x

CVE-2022-36123

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.5-LTS

3.1.x
3.0.x

CVE-2022-36946

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.5-LTS

3.1.x
3.0.x

CVE-2022-36879

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.5-LTS

3.1.x
3.0.x

CVE-2022-2327

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.5-LTS

3.1.x
3.0.x

CVE-2022-21505

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.5-LTS

3.1.x
3.0.x

CVE-2021-33655

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.5-LTS

3.1.x
3.0.x

CVE-2021-33656

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.5-LTS

3.1.x
3.0.x

CVE-2022-2861

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release

3.1.x

CVE-2022-2860

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release

3.1.x

CVE-2022-2613

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release

3.1.x

CVE-2022-2612

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release

3.1.x

CVE-2022-2610

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release

3.1.x

CVE-2022-2607

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release

3.1.x

CVE-2022-2606

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release

3.1.x

CVE-2022-2624

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release

3.1.x

CVE-2022-2623

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release

3.1.x

CVE-2022-2620

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release

3.1.x

CVE-2022-2619

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release

3.1.x

CVE-2022-2617

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release

3.1.x

CVE-2022-2616

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release

3.1.x

CVE-2022-2615

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release

3.1.x

CVE-2022-2614

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release

3.1.x

CVE-2022-35737

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.5-LTS

3.1.x
3.0.x

CVE-2022-2415

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release

3.1.x

CVE-2022-1919

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release

3.1.x

CVE-2022-35252

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.6-LTS
OpenHarmony-v1.1.0-release
OpenHarmony-v1.1.5-LTS

3.1.x
3.0.x
1.1.x

CVE-2022-3028

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.6-LTS

3.1.x
3.0.x

CVE-2022-2977

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.6-LTS

3.1.x
3.0.x

CVE-2022-2964

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.6-LTS

3.1.x
3.0.x

CVE-2022-39188

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.6-LTS

3.1.x
3.0.x

CVE-2022-3078

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.6-LTS

3.1.x
3.0.x

CVE-2022-2905

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.6-LTS

3.1.x
3.0.x

CVE-2022-39842

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.6-LTS

3.1.x
3.0.x

CVE-2022-3061

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.6-LTS

3.1.x
3.0.x

CVE-2021-29921

严重

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release

3.1.x

CVE-2022-0391

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release

3.1.x

CVE-2021-3737

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release

3.1.x

CVE-2021-4189

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release

3.1.x

CVE-2021-3733

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release

3.1.x

CVE-2021-28861

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.2-Release

3.1.x

CVE-2022-40307

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.3-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.6-LTS

3.1.x
3.0.x