OpenHarmony Kernel LiteOS A Use-After-Free Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A use-after-free vulnerability has been identified in the OpenHarmony kernel LiteOS A component, specifically in versions through 5.0.3. This vulnerability allows local attackers to execute arbitrary code within the Trusted Computing Base (TCB).

Impact

Exploitation of this vulnerability could lead to unauthorized arbitrary code execution within the TCB, potentially allowing attackers to manipulate system processes or resources at a fundamental level.

Remediation

Users can apply the available patch by updating to the OpenHarmony 5.0.3 release version. Instructions for applying the patch can be found in the OpenHarmony kernel LiteOS A repository on Gitee.

Added: Aug 11, 2025, 4:25 AM
Updated: Aug 11, 2025, 4:25 AM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
7.5
exploitability
3.3
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.