Impact
The vulnerability is a use‑after‑free in a kernel module. Successful exploitation can compromise the device’s availability and confidentiality, as stated in the official description.
Affected Systems
Huawei devices running EMUI or HarmonyOS are affected. The advisory does not list specific versions, so any release that includes the vulnerable kernel module may be at risk.
Risk and Exploitability
The CVSS score of 5.7 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, implying no known public exploits yet. Because the flaw resides in the kernel, the likely attack vector requires local or privileged access, as inferred from the nature of use‑after‑free bugs. The risk is non‑trivial if an attacker can gain such access.
OpenCVE Enrichment