发布于2025.09.02

备注:OpenHarmony 5.0阶段各分支中当前主要对OpenHarmony-5.0.3-Release分支进行安全漏洞维护。

CVE漏洞描述漏洞影响严重程度CVSS 3.1得分受影响的版本受影响的仓库修复链接
CVE-2025-26474communication_ipc 不当输入验证漏洞特定场景下, 本地攻击者可造成信息泄露低危3.3OpenHarmony-v5.0.3-Releasecommunication_ipc5.0.3.x
CVE-2025-6969ability_ability_runtime 权限绕过漏洞本地攻击者可造成DOS中危5.0OpenHarmony-v5.0.3-Release) OpenHarmony-v5.1.0-Releaseability_ability_runtime5.0.3.x 5.1.0.x

以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本,详细信息请参考三方公告。

CVE严重程度CVSS 3.1得分受影响的仓库受影响的OpenHarmony版本修复链接
CVE-2025-38466尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-38424尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-38347尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-38346尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-38337尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-38328尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-38320尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-38312尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-38285尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-38222尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-38219尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-38218尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-38215尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-38214尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-38212高危8.0kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-38206尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-38194中危4.6kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-38181尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-38180高危8.0kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-38166尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-38163尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-38147尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-38126尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-38125尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-38124中危5.5kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-38117尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-38111尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-38103尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-38097尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-38095尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-38079尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-38068尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-38067尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-38062尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-38058尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-38057尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-38023尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-37995中危5.5kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-37980中危5.7kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-37959中危5.5kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-37940低危4.8kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-37937中危5.7kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-37923低危2.6kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-37862尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-37859尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-37841中危5.7kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-37839中危5.5kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-37836中危5.7kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-37810低危2.6kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-37808中危5.5kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-37807低危4.8kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-22113尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-22008尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-21959尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-21922尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-21910尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-21909尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-21881尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-21838尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-21817中危4.8kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-21766中危3.5kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-21765中危3.5kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-21758尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-21708尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2024-58093尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2024-57986中危5.7kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2024-57982中危3.5kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2024-57974中危5.3kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2024-57876高危8.0kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2024-57850高危8.0kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2024-56780中危4.8kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2024-56751尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2024-56719尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2024-53237尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2024-53196尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2024-41062尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2024-36484尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2024-26947尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2024-26869中危4.7kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2023-53001中危5.7kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2023-52621高危7.8kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2023-52608中危4.7kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2022-50167尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2022-50100尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2022-49967尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2022-49961尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2022-49837尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2022-49801尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2022-49728尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2022-49579尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2022-49513尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2022-49444尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2022-49266尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2022-49169尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2021-47618中危4.8kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x

以下是各维护版本的安全补丁标签,请在合入当月及之前全部对应安全补丁之后,更新安全补丁标签。

对应维护版本安全补丁修改方式参考链接
5.1.0.xhttps://gitee.com/openharmony/startup_init/pulls/4062
5.0.3.xhttps://gitee.com/openharmony/startup_init/pulls/4063