OpenHarmony-v3.1.2 and prior versions, 3.0.6 and prior versions have an Out-of-bound memory read and write vulnerability in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged process run on the device could read out-of-bound memory leading sensitive to information disclosure. The processes with system user UID run on the device would be able to write out-of-bound memory which could lead to unspecified memory corruption.
Metrics
Affected Vendors & Products
References
History
Mon, 09 Sep 2024 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Openatom
Openatom openharmony |
|
CPEs | cpe:2.3:o:openatom:openharmony:*:*:*:*:-:*:*:* | |
Vendors & Products |
Openatom
Openatom openharmony |
MITRE
Status: PUBLISHED
Assigner: OpenHarmony
Published: 2022-10-14T14:40:04.568847Z
Updated: 2024-09-17T03:03:30.412Z
Reserved: 2022-10-08T00:00:00
Link: CVE-2022-41686
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-10-14T15:16:20.347
Modified: 2024-11-21T07:23:38.813
Link: CVE-2022-41686
Redhat
No data.