Impact
This vulnerability is a use‑after‑free flaw in the package management module of Huawei HarmonyOS. The flaw can lead to compromised service integrity, potentially causing the affected services to crash or behave unpredictably. The weakness is classified as CWE‑284, indicating an access control issue that allows improper handling of memory resources during package operations.
Affected Systems
The affected system is Huawei HarmonyOS. No specific affected versions are listed in the available CNA data.
Risk and Exploitability
The CVSS score of 5.2 indicates moderate severity. The EPSS score is not available, so the likelihood of exploitation is unclear. The vulnerability is not included in CISA’s KEV catalog. Remaining inference suggests the attack vector may be local, arising during package installation or removal, but the precise conditions are not explicitly stated in the advisory.
OpenCVE Enrichment