The kernel subsystem function check_permission_for_set_tokenid within OpenHarmony-v3.1.5 and prior versions has an UAF vulnerability which local attackers can exploit this vulnerability to escalate the privilege to root.
References
Link | Resource |
---|---|
https://gitee.com/openharmony/security/blob/master/en/security-disclosure/2023/2023-02.md | Third Party Advisory |
Configurations
Information
Published : 2023-03-10 03:15
Updated : 2023-03-14 10:59
NVD link : CVE-2023-22436
Mitre link : CVE-2023-22436
JSON object : View
CWE
CWE-416
Use After Free
Products Affected
openharmony
- openharmony