Description
Null pointer dereference issue in the image codec module. Impact: Successful exploitation of this vulnerability may affect availability.
Published: 2026-08-17
Score: 4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A null pointer dereference was found in the image codec module of HarmonyOS. When a corrupted image is decoded, the codec can crash, causing the affected process or device to become unavailable. The primary consequence is service interruption rather than data loss or disclosure.

Affected Systems

The vulnerability affects devices running Huawei HarmonyOS. No specific device families or software versions are listed, so all released HarmonyOS installations potentially carry the flaw.

Risk and Exploitability

The CVSS score is 4, indicating moderate severity. With no EPSS score published and the issue not marked in the KEV catalog, the likelihood of widespread exploitation is currently low. Based on the description, the likely attack vector involves the delivery of a malformed image—either locally or remotely—to the codec module, triggering a crash and denial of service.

Generated by OpenCVE AI on August 17, 2026 at 11:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Huawei’s support site for a HarmonyOS patch or update that addresses the null pointer issue.
  • If a recommended update is available, apply it to all affected devices as soon as possible.
  • Restrict or sandbox applications from processing untrusted image files until an official fix is deployed.
  • Continuously monitor device stability and promptly report any crashes related to image handling to Huawei support.

Generated by OpenCVE AI on August 17, 2026 at 11:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Title Null Pointer Dereference in HarmonyOS Image Codec Module

Mon, 17 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Huawei
Huawei harmonyos
Vendors & Products Huawei
Huawei harmonyos

Mon, 17 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description Null pointer dereference issue in the image codec module. Impact: Successful exploitation of this vulnerability may affect availability.
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Huawei Harmonyos
cve-icon MITRE

Status: PUBLISHED

Assigner: huawei

Published:

Updated: 2026-08-17T11:32:13.885Z

Reserved: 2026-07-01T10:03:11.403Z

Link: CVE-2026-58561

cve-icon Vulnrichment

Updated: 2026-08-17T11:32:06.487Z

cve-icon NVD

Status : Deferred

Published: 2026-08-17T09:17:31.290

Modified: 2026-08-26T16:33:17.117

Link: CVE-2026-58561

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T11:15:04Z

Weaknesses