Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysTimerGettime. 4 bytes padding data from kernel stack are copied to user space incorrectly and leaked.
2023-01-09T03:15:09.327
2024-11-21T07:26:59.600
Modified
CVSSv3.1: 4.0 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | openharmony | openharmony | ≤ 3.1.4 | Yes |
Operating System | openatom | openharmony | ≤ 1.1.5 | Yes |
Operating System | openatom | openharmony | ≤ 3.0.6 | Yes |