发布于2024.08.06

以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本,详细信息请参考三方公告。

CVE严重程度CVSS 3.1得分受影响的仓库受影响的OpenHarmony版本修复链接
CVE-2024-3914低危3.6web_webviewOpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.0.x 4.1.x
CVE-2024-3843低危2.7web_webviewOpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-3841低危2.7web_webviewOpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-4671致命9.6web_webviewOpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-4603中危5.3third_party_opensslOpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-4761高危8.8web_webviewOpenHarmony-v4.0-Release4.0.x
CVE-2024-5274高危8.8web_webviewOpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-4947高危8.8web_webviewOpenHarmony-v4.0-Release4.0.x
CVE-2024-3840低危2.7web_webviewOpenHarmony-v4.1-Release4.1.x 4.1.x 4.1.x
CVE-2024-4331低危3.1web_webviewOpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.1.x
CVE-2024-4558低危3.1web_webviewOpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-5158低危2.7web_webviewOpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-3845低危2.7web_webviewOpenHarmony-v4.1-Release4.1.x 4.1.x
CVE-2024-35807中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-35978中危5.7kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-35950中危5.7kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-27431中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-35815低危3.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-5159中危4.7web_webviewOpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-5157低危0.0web_webviewOpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-36941中危5.7kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-36940中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-36939中危4.6kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-36938中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-36929中危5.7kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-36905中危4.6kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-36904高危7.1kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-36903中危4.8kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-36902中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-36901中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-36899高危7.1kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-36883低危3.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-36017低危3.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-36008中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-35997中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-35984中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-35969中危4.6kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-35962中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-35955中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-35910中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-35904中危5.7kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-35896低危2.6kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-35822低危3.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-35789中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-35785中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-28182中危5.3third_party_nghttp2OpenHarmony-v4.0-Release4.0.x
CVE-2024-27417中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-27414中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-27399中危5.3kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-27013中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-26934高危7.8kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2024-26805低危2.7kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2024-26801低危2.7kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2024-26735低危2.7kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2024-26733低危2.7kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2024-26601中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2023-52881低危3.7kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2023-52879低危2.7kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2023-52869低危2.7kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2023-52868低危2.7kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2023-52845中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2023-52835低危3.8kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2023-52832低危2.7kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2023-52803中危4.6kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2023-52781低危3.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2023-52756低危2.7kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2023-52739低危2.7kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2023-52730中危4.7kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2023-52462中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x
CVE-2023-52454中危5.5kernel_linux_5.10OpenHarmony-v4.0-Release4.0.x
CVE-2021-47469低危2.7kernel_linux_5.10OpenHarmony-v4.0-Release OpenHarmony-v4.1-Release4.0.x 4.1.x

如下是各维护版本的安全补丁标签,请在合入当月及之前全部对应安全补丁之后,更新安全补丁标签。

安全补丁标签链接
2024年08月[4.1.x]
[4.0.x]