发布于2026.01.06

备注:OpenHarmony 5.0阶段各分支中当前主要对OpenHarmony-5.0.3-Release分支进行安全漏洞维护。

以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本,详细信息请参考三方公告。

CVE严重程度CVSS 3.1得分受影响的仓库受影响的OpenHarmony版本修复链接
CVE-2025-40105尚未提供kernel_linux_5.10OpenHarmony-v6.0-Release OpenHarmony-v5.1.0-Release OpenHarmony-v5.0.3-Release6.0.x 5.1.0.x 5.0.3.x
CVE-2025-40102尚未提供kernel_linux_5.10OpenHarmony-v6.0-Release OpenHarmony-v5.1.0-Release OpenHarmony-v5.0.3-Release6.0.x 5.1.0.x 5.0.3.x
CVE-2025-40077尚未提供kernel_linux_5.10OpenHarmony-v6.0-Release OpenHarmony-v5.1.0-Release OpenHarmony-v5.0.3-Release6.0.x 5.1.0.x 5.0.3.x
CVE-2025-40064尚未提供kernel_linux_5.10OpenHarmony-v6.0-Release OpenHarmony-v5.1.0-Release OpenHarmony-v5.0.3-Release6.0.x 5.1.0.x 5.0.3.x
CVE-2025-40054尚未提供kernel_linux_5.10OpenHarmony-v6.0-Release OpenHarmony-v5.1.0-Release OpenHarmony-v5.0.3-Release6.0.x 5.1.0.x 5.0.3.x
CVE-2025-40049尚未提供kernel_linux_5.10OpenHarmony-v6.0-Release OpenHarmony-v5.1.0-Release OpenHarmony-v5.0.3-Release6.0.x 5.1.0.x 5.0.3.x
CVE-2025-40035尚未提供kernel_linux_5.10OpenHarmony-v6.0-Release OpenHarmony-v5.1.0-Release OpenHarmony-v5.0.3-Release6.0.x 5.1.0.x 5.0.3.x
CVE-2025-40021尚未提供kernel_linux_5.10OpenHarmony-v6.0-Release OpenHarmony-v5.1.0-Release OpenHarmony-v5.0.3-Release6.0.x 5.1.0.x 5.0.3.x
CVE-2025-40016尚未提供kernel_linux_5.10OpenHarmony-v6.0-Release OpenHarmony-v5.1.0-Release OpenHarmony-v5.0.3-Release6.0.x 5.1.0.x 5.0.3.x
CVE-2025-39946尚未提供kernel_linux_6.6OpenHarmony-v6.0-Release6.0.x
CVE-2025-39914尚未提供kernel_linux_6.6OpenHarmony-v6.0-Release6.0.x
CVE-2025-39806尚未提供kernel_linux_6.6OpenHarmony-v6.0-Release6.0.x
CVE-2025-39782尚未提供kernel_linux_5.10OpenHarmony-v5.0.3-Release5.0.3.x
CVE-2025-39749尚未提供kernel_linux_5.10OpenHarmony-v6.0-Release OpenHarmony-v5.1.0-Release OpenHarmony-v5.0.3-Release6.0.x 5.1.0.x 5.0.3.x
CVE-2025-39702尚未提供kernel_linux_5.10OpenHarmony-v6.0-Release OpenHarmony-v5.1.0-Release OpenHarmony-v5.0.3-Release6.0.x 5.1.0.x 5.0.3.x
CVE-2024-47674中危5.7kernel_linux_5.10OpenHarmony-v6.0-Release OpenHarmony-v5.1.0-Release6.0.x 5.1.0.x
CVE-2024-38594中危5.5kernel_linux_5.10OpenHarmony-v6.0-Release OpenHarmony-v5.1.0-Release6.0.x 5.1.0.x
CVE-2023-53673尚未提供kernel_linux_5.10OpenHarmony-v6.0-Release OpenHarmony-v5.1.0-Release OpenHarmony-v5.0.3-Release6.0.x 5.1.0.x 5.0.3.x
CVE-2023-53596尚未提供kernel_linux_5.10OpenHarmony-v6.0-Release OpenHarmony-v5.1.0-Release OpenHarmony-v5.0.3-Release6.0.x 5.1.0.x 5.0.3.x
CVE-2023-53594尚未提供kernel_linux_5.10OpenHarmony-v6.0-Release OpenHarmony-v5.1.0-Release OpenHarmony-v5.0.3-Release6.0.x 5.1.0.x 5.0.3.x
CVE-2023-53520尚未提供kernel_linux_5.10OpenHarmony-v6.0-Release OpenHarmony-v5.1.0-Release OpenHarmony-v5.0.3-Release6.0.x 5.1.0.x 5.0.3.x
CVE-2023-53491尚未提供kernel_linux_5.10OpenHarmony-v6.0-Release OpenHarmony-v5.1.0-Release OpenHarmony-v5.0.3-Release6.0.x 5.1.0.x 5.0.3.x
CVE-2023-53482尚未提供kernel_linux_5.10OpenHarmony-v6.0-Release OpenHarmony-v5.1.0-Release OpenHarmony-v5.0.3-Release6.0.x 5.1.0.x 5.0.3.x
CVE-2022-49054尚未提供kernel_linux_5.10OpenHarmony-v6.0-Release OpenHarmony-v5.1.0-Release OpenHarmony-v5.0.3-Release6.0.x 5.1.0.x 5.0.3.x

以下是各维护版本的安全补丁标签,请在合入当月及之前全部对应安全补丁之后,更新安全补丁标签。

对应维护版本安全补丁修改方式参考链接
6.0.xhttps://gitcode.com/openharmony/startup_init/pull/4306
5.1.0.xhttps://gitcode.com/openharmony/startup_init/pull/4315
5.0.3.xhttps://gitcode.com/openharmony/startup_init/pull/4305