PT-2022-26079 · Unknown · Openharmony

Published

2022-12-08

·

Updated

2024-09-09

·

CVE-2022-41802

CVSS v3.1

4.0

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions OpenHarmony versions prior to 3.1.4
Description The kernel subsystem within OpenHarmony has a kernel stack overflow issue when the SysClockGetres function is called. This results in 4 bytes of padding data from the kernel stack being copied to user space incorrectly and leaked.
Recommendations For OpenHarmony versions prior to 3.1.4, update to a version that includes the fix for this issue to prevent the kernel stack overflow vulnerability when calling SysClockGetres. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2022-41802

Affected Products

Openharmony