OpenHarmony Kernel LiteOS A Use-After-Free Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A use-after-free vulnerability has been identified in the OpenHarmony kernel LiteOS A component, in versions through 5.0.3. This vulnerability allows local attackers to execute arbitrary code within the Trusted Computing Base (TCB).

Impact

Exploitation of this vulnerability could lead to unauthorized arbitrary code execution within the TCB.

Remediation

Users can apply the available patch by merging the pull request #1279 on the OpenHarmony kernel_liteos_a repository.

Added: Aug 11, 2025, 4:36 AM
Updated: Aug 11, 2025, 4:36 AM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
7.5
exploitability
3.3
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.