CVE-2022-38701: IPC in communication subsystem has a heap overflow vulnerability. Local attackers can trigger a heap overflow and get network sensitive information.
Published Sep 9, 2022
·Updated
OpenHarmony-v3.1.2 and prior versions have a heap overflow vulnerability. Local attackers can trigger a heap overflow and get network sensitive information.
Affected Software
3 affected components
OpenHarmony OpenHarmony>=3.0<=3.0.5
Openatom Openharmony>=3.1<=3.1.2
OpenHarmony OpenHarmony>=3.1<=3.1.2
Event History
Sep 9, 2022
CVE Published
via MITRE·02:39 PM
Data Sourced
via MITRE·02:39 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this OpenHarmony vulnerability?
The vulnerability ID for this OpenHarmony vulnerability is CVE-2022-38701.
2
What is the severity of CVE-2022-38701?
The severity of CVE-2022-38701 is medium, with a severity value of 3.3.
3
How can local attackers exploit CVE-2022-38701?
Local attackers can exploit CVE-2022-38701 by triggering a heap overflow and obtaining network-sensitive information.
4
Which versions of OpenHarmony are affected by CVE-2022-38701?
OpenHarmony v3.1.2 and prior versions, including v3.0 to v3.0.5, are affected by CVE-2022-38701.
5
Is there a fix available for CVE-2022-38701?
Please refer to the OpenHarmony security advisory for information on available fixes for CVE-2022-38701.