Description
Out-of-bounds read vulnerability in the graphics module. Successful exploitation of this vulnerability may affect availability.
Published: 2026-09-24
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: Availability impact
Action: Monitor
AI Analysis

Impact

This vulnerability is an out-of-bounds read in the graphics module, which can lead to a loss of service or system instability. The weakness is categorized as CWE-125, indicating that an attacker may manipulate memory bounds during graphics processing. An exploited exploit can cause the device to crash or become unresponsive, compromising the availability of the affected system.

Affected Systems

The vulnerability affects Huawei HarmonyOS devices. Specific model or firmware version details are not disclosed in the advisory.

Risk and Exploitability

The CVSS score of 5.9 indicates a moderate severity. Because no EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, the likelihood of widespread exploitation is uncertain. The attack vector is not explicitly defined, but it is reasonable to infer that an attacker would need some level of interaction with the graphics subsystem, possibly through predetermined graphics input or a malicious application. If exploited, the attacker could cause a denial of service on the targeted device.

Generated by OpenCVE AI on September 24, 2026 at 07:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest HarmonyOS firmware update when released.
  • Restrict access to the graphics module to trusted system processes only.
  • Monitor device logs for crashes or instability that may indicate graphics-related issues.

Generated by OpenCVE AI on September 24, 2026 at 07:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in HarmonyOS Graphics Module
First Time appeared Huawei
Huawei harmonyos
Vendors & Products Huawei
Huawei harmonyos

Thu, 24 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Description Out-of-bounds read vulnerability in the graphics module. Successful exploitation of this vulnerability may affect availability.
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Huawei Harmonyos
cve-icon MITRE

Status: PUBLISHED

Assigner: huawei

Published:

Updated: 2026-09-24T06:18:16.593Z

Reserved: 2026-08-27T09:26:59.599Z

Link: CVE-2026-81645

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-24T07:16:33.307

Modified: 2026-09-24T07:16:33.307

Link: CVE-2026-81645

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T07:30:16Z

Weaknesses