OpenHarmony LiteOS_A Kernel Use-After-Free Vulnerability Allowing Privilege Escalation

Vulnerability

A use-after-free vulnerability has been identified in the OpenHarmony LiteOS_A kernel, in versions through 4.1.2. This vulnerability allows a local attacker to escalate privileges by upgrading common permissions to root, and it also leads to the leakage of sensitive information.

Impact

Exploitation of this vulnerability allows local attackers to gain root privileges and access sensitive information.

Remediation

Users can apply the patch available in the OpenHarmony kernel_liteos_a repository, specifically in the 4.1.x branch.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
7.5
exploitability
3.3
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.