OpenHarmony Race Condition Vulnerability in Kernel LiteOS A Allowing Arbitrary Code Execution

Vulnerability

A race condition vulnerability has been identified in the OpenHarmony operating system, specifically in the kernel_liteos_a component, in versions through 5.0.3. This vulnerability allows local attackers to execute arbitrary code within the Trusted Computing Base (TCB).

Impact

Exploitation of this vulnerability could lead to unauthorized execution of code within the kernel, potentially allowing attackers to escalate privileges or manipulate system processes.

Remediation

Users can apply the available patch by merging the pull request #1298 into their OpenHarmony v5.0.3 release branch.

Added: Aug 11, 2025, 4:20 AM
Updated: Aug 11, 2025, 4:20 AM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
7.5
exploitability
2.9
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.