发布于2026.08.04 备注:OpenHarmony-5.0.3-Release分支当前已停止维护,后续这个分支的安全漏洞也不再维护,详情参见社区公告。 OpenHarmony-5.0.3-Release分支停止维护公告 CVE漏洞描述漏洞影响严重程度CVSS3.1基础得分受影响的版本受影响的仓库修复链接 CVE-2026-50001communication_bluetooth 权限绕过漏洞本地攻击者可造成DOS低危3.3OpenHarmony-v6.1-Releasecommunication_bluetooth6.1.x CVE-2026-41955web_webview 越界读漏洞远程攻击者可造成DOS中危6.5OpenHarmony-v5.1.0-Release OpenHarmony-v6.0-Releaseweb_webview6.0.x 5.1.0.x CVE-2026-50049arkcompiler_ets_runtime 越界写漏洞本地攻击者可造成任意代码执行中危5.5OpenHarmony-v6.0-Releasearkcompiler_ets_runtime6.0.x CVE-2026-21395arkui_ace_engine 越界写漏洞本地攻击者可造成任意代码执行中危5.5OpenHarmony-v5.1.0-Releasearkui_ace_engine5.1.0.x CVE-2026-49031kernel_liteos_a 越界写漏洞本地攻击者可造成任意代码执行高危7.8OpenHarmony-v5.1.0-Release OpenHarmony-v6.0-Release OpenHarmony-v6.1-Releasekernel_liteos_a6.0.x 5.1.0.x 6.1.x CVE-2026-50051kernel_liteos_a 越界写漏洞本地攻击者可造成DOS低危3.3OpenHarmony-v5.1.0-Release OpenHarmony-v6.0-Release OpenHarmony-v6.1-Releasekernel_liteos_a6.0.x 5.1.0.x 6.1.x CVE-2026-40625kernel_liteos_m 空指针解引用漏洞本地攻击者可造成任意代码执行中危6.0OpenHarmony-v5.1.0-Release OpenHarmony-v6.0-Release OpenHarmony-v6.1-Releasekernel_liteos_m6.0.x 5.1.0.x 6.1.x CVE-2026-57888kernel_liteos_a 越界写漏洞本地攻击者可造成任意代码执行中危5.5OpenHarmony-v5.1.0-Release OpenHarmony-v6.0-Release OpenHarmony-v6.1-Releasekernel_liteos_a6.0.x 5.1.0.x 6.1.x CVE-2026-59777kernel_liteos_a 不当输入验证漏洞本地攻击者可造成DOS低危3.3OpenHarmony-v5.1.0-Release OpenHarmony-v6.0-Release OpenHarmony-v6.1-Releasekernel_liteos_a6.0.x 5.1.0.x 6.1.x CVE-2026-58516kernel_liteos_a 不当输入验证漏洞本地攻击者可造成任意代码执行高危7.1OpenHarmony-v5.1.0-Release OpenHarmony-v6.0-Release OpenHarmony-v6.1-Releasekernel_liteos_a6.0.x 5.1.0.x 6.1.x CVE-2026-56753kernel_liteos_a 不当输入验证漏洞本地攻击者可造成DOS低危1.9OpenHarmony-v5.1.0-Release OpenHarmony-v6.0-Release OpenHarmony-v6.1-Releasekernel_liteos_a6.0.x 5.1.0.x 6.1.x CVE-2026-59760multimedia_av_codec 不当输入验证漏洞本地攻击者可造成信息泄露中危4.3OpenHarmony-v6.0-Release OpenHarmony-v6.1-Releasemultimedia_av_codec6.0.x 6.1.x CVE-2026-55989multimedia_audio_framework 空指针解引用漏洞本地攻击者可造成DOS低危3.3OpenHarmony-v6.1-Releasemultimedia_audio_framework6.1.x CVE-2026-56656base_location 敏感信息泄露漏洞本地攻击者可造成信息泄露低危3.3OpenHarmony-v6.1-Releasebase_location6.1.x CVE-2026-58313bundlemanager_app_domain_verify UAF漏洞本地攻击者可造成任意代码执行高危7.8OpenHarmony-v6.1-Releasebundlemanager_app_domain_verify6.1.x 以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本,详细信息请参考三方公告。 CVE严重程度CVSS 3.1得分受影响的仓库受影响的OpenHarmony版本修复链接 CVE-2026-40200高危8.1third_party_muslOpenHarmony-v6.0-Release OpenHarmony-v6.1-Release6.0.x 6.1.x CVE-2025-71077无尚未提供kernel_linux_6.6OpenHarmony-v6.0-Release OpenHarmony-v6.1-Release6.0.x 6.1.x CVE-2025-68742无尚未提供kernel_linux_6.6OpenHarmony-v6.0-Release OpenHarmony-v6.1-Release6.0.x 6.1.x CVE-2025-68282无尚未提供kernel_linux_6.6OpenHarmony-v6.0-Release OpenHarmony-v6.1-Release6.0.x 6.1.x CVE-2025-62408中危5.9third_party_caresOpenHarmony-v6.1-Release6.1.x CVE-2025-40164无尚未提供kernel_linux_6.6OpenHarmony-v6.0-Release OpenHarmony-v6.1-Release6.0.x 6.1.x CVE-2025-21691无尚未提供kernel_linux_6.6OpenHarmony-v6.0-Release OpenHarmony-v6.1-Release6.0.x 6.1.x CVE-2025-21665中危5.5kernel_linux_6.6OpenHarmony-v6.0-Release OpenHarmony-v6.1-Release6.0.x 6.1.x CVE-2024-58078中危5.5kernel_linux_6.6OpenHarmony-v6.0-Release OpenHarmony-v6.1-Release6.0.x 6.1.x CVE-2024-57951无尚未提供kernel_linux_6.6OpenHarmony-v6.0-Release OpenHarmony-v6.1-Release6.0.x 6.1.x CVE-2024-57930无尚未提供kernel_linux_6.6OpenHarmony-v6.0-Release OpenHarmony-v6.1-Release6.0.x 6.1.x CVE-2024-53206无尚未提供kernel_linux_6.6OpenHarmony-v6.0-Release OpenHarmony-v6.1-Release6.0.x 6.1.x CVE-2024-45002中危5.5kernel_linux_6.6OpenHarmony-v6.0-Release OpenHarmony-v6.1-Release6.0.x 6.1.x CVE-2024-40908无尚未提供kernel_linux_6.6OpenHarmony-v6.0-Release OpenHarmony-v6.1-Release6.0.x 6.1.x CVE-2024-38620无尚未提供kernel_linux_6.6OpenHarmony-v6.0-Release OpenHarmony-v6.1-Release6.0.x 6.1.x CVE-2024-23848中危5.5kernel_linux_6.6OpenHarmony-v6.0-Release OpenHarmony-v6.1-Release6.0.x 6.1.x 以下是各维护版本的安全补丁标签,请在合入当月及之前全部对应安全补丁之后,更新安全补丁标签。 对应维护版本安全补丁修改方式参考链接 6.1.xhttps://gitcode.com/openharmony/startup_init/pull/4767 6.0.xhttps://gitcode.com/openharmony/startup_init/pull/4766 5.1.0.xhttps://gitcode.com/openharmony/startup_init/pull/4765
participants (1)
-
王晨