发布于2026.07.07 备注:OpenHarmony-5.0.3-Release分支当前已停止维护,后续这个分支的安全漏洞也不再维护,详情参见社区公告。 OpenHarmony-5.0.3-Release分支停止维护公告 CVE漏洞描述漏洞影响CVSS3.1基础得分受影响的版本受影响的仓库修复链接 CVE-2026-35497filemanagement_storage_service 敏感信息保存不当漏洞本地攻击者可造成信息泄露3.3OpenHarmony-v5.1.0-Release OpenHarmony-v6.0-Releasefilemanagement_storage_service6.0.x 5.1.0.x CVE-2026-49029drivers_hdf_core 数组越界访问漏洞本地攻击者可造成信息泄露3.3OpenHarmony-v6.0-Releasedrivers_hdf_core6.0.x CVE-2026-49032communication_netmanager_base 不当输入验证漏洞本地攻击者可造成DOS3.3OpenHarmony-v6.0-Releasecommunication_netmanager_base6.0.x CVE-2026-44610kernel_liteos_a 敏感信息保存不当漏洞本地攻击者可造成信息泄露3.3OpenHarmony-v5.1.0-Release OpenHarmony-v6.0-Release OpenHarmony-v6.1-Releasekernel_liteos_a6.0.x 5.1.0.x 6.1.X CVE-2026-44384kernel_liteos_a 敏感信息保存不当漏洞本地攻击者可造成信息泄露3.3OpenHarmony-v5.1.0-Release OpenHarmony-v6.0-Release OpenHarmony-v6.1-Releasekernel_liteos_a6.0.x 5.1.0.x 6.1.X CVE-2026-42939kernel_liteos_a 越界读漏洞本地攻击者可造成信息泄露3.3OpenHarmony-v5.1.0-Release OpenHarmony-v6.0-Release OpenHarmony-v6.1-Releasekernel_liteos_a6.0.x 5.1.0.x 6.1.X CVE-2026-42921kernel_liteos_a 越界读漏洞本地攻击者可造成信息泄露3.3OpenHarmony-v5.1.0-Release OpenHarmony-v6.0-Release OpenHarmony-v6.1-Releasekernel_liteos_a6.0.x 5.1.0.x 6.1.X CVE-2026-46577kernel_liteos_a 越界读漏洞本地攻击者可造成信息泄露3.3OpenHarmony-v5.1.0-Release OpenHarmony-v6.0-Release OpenHarmony-v6.1-Releasekernel_liteos_a6.0.x 5.1.0.x 6.1.X CVE-2026-42068kernel_liteos_a 越界读漏洞本地攻击者可造成信息泄露3.3OpenHarmony-v5.1.0-Release OpenHarmony-v6.0-Release OpenHarmony-v6.1-Releasekernel_liteos_a6.0.x 5.1.0.x 6.1.X CVE-2026-42957kernel_liteos_a 越界写漏洞本地攻击者可造成任意代码执行6.0OpenHarmony-v5.1.0-Release OpenHarmony-v6.0-Releas OpenHarmony-v6.1-Releasekernel_liteos_a6.0.x 5.1.0.x 6.1.X CVE-2026-50004base_location 不当输入验证漏洞本地攻击者可造成DOS3.3OpenHarmony-v6.0-Release OpenHarmony-v6.1-Releasebase_location6.0.x 6.1.X CVE-2026-44391base_location 不当输入验证漏洞本地攻击者可造成DOS3.3OpenHarmony-v5.1.0-Release OpenHarmony-v6.0-Releasebase_location6.0.x 5.1.0.x CVE-2026-49037base_location 不当输入验证漏洞本地攻击者可造成DOS3.3OpenHarmony-v6.0-Release OpenHarmony-v6.1-Releasebase_location6.0.x 6.1.X CVE-2026-27789kernel_liteos_a 条件竞争漏洞本地攻击者可造成信息泄露3.3OpenHarmony-v5.1.0-Release OpenHarmony-v6.0-Release OpenHarmony-v6.1-Releasekernel_liteos_a6.0.x 5.1.0.x 6.1.X CVE-2026-33087kernel_liteos_a 条件竞争漏洞本地攻击者可造成信息泄露3.3OpenHarmony-v5.1.0-Release OpenHarmony-v6.0-Release OpenHarmony-v6.1-Releasekernel_liteos_a6.0.x 5.1.0.x 6.1.X CVE-2026-33561kernel_liteos_a 条件竞争漏洞本地攻击者可造成信息泄露3.3OpenHarmony-v5.1.0-Release OpenHarmony-v6.0-Release OpenHarmony-v6.1-Releasekernel_liteos_a6.0.x 5.1.0.x 6.1.X CVE-2026-35059kernel_liteos_a 条件竞争漏洞本地攻击者可造成信息泄露3.3OpenHarmony-v5.1.0-Release OpenHarmony-v6.0-Release OpenHarmony-v6.1-Releasekernel_liteos_a6.0.x 5.1.0.x 6.1.X 以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本,详细信息请参考三方公告。 CVE严重程度CVSS 3.1得分受影响的仓库受影响的OpenHarmony版本修复链接 CVE-2026-25210中危6.9third_party_skiaOpenHarmony-v6.0-Release OpenHarmony-v6.1-Release6.0.x 6.1.X CVE-2026-24515低危2.5third_party_skiaOpenHarmony-v6.0-Release OpenHarmony-v6.1-Release6.0.x 6.1.X CVE-2026-6732中危6.5third_party_libxml2OpenHarmony-v5.1.0-Release OpenHarmony-v6.0-Release OpenHarmony-v6.1-Release6.0.x 5.1.0.x 6.1.X CVE-2026-34757中危5.1third_party_libpngOpenHarmony-v6.0-Release OpenHarmony-v6.1-Release6.0.x 6.1.X CVE-2025-8291中危4.3third_party_pythonOpenHarmony-v6.0-Release6.0.x 以下是各维护版本的安全补丁标签,请在合入当月及之前全部对应安全补丁之后,更新安全补丁标签。 对应维护版本安全补丁修改方式参考链接 6.1.xhttps://gitcode.com/openharmony/startup_init/pull/4767 6.0.xhttps://gitcode.com/openharmony/startup_init/pull/4766 5.1.0.xhttps://gitcode.com/openharmony/startup_init/pull/4765
participants (1)
-
王晨