OpenHarmony Race Condition Vulnerability in Kernel Leading to Arbitrary Code Execution

Vulnerability

A race condition vulnerability has been identified in the OpenHarmony operating system, specifically in versions through 5.0.3. This vulnerability allows local attackers to execute arbitrary code within the Trusted Computing Base (TCB) of the system.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of code within the kernel, potentially allowing attackers to escalate privileges or interfere with system processes.

Remediation

Users can apply the security patch available in the OpenHarmony 5.0.3.x maintenance branch. Instructions for updating this branch are available on Gitee.

Added: Aug 11, 2025, 4:29 AM
Updated: Aug 11, 2025, 4:29 AM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
7.5
exploitability
2.9
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.