CVE-2022-41802: Kernel subsystem in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGetres.
Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernelliteosa has a kernel stack overflow vulnerability when call SysClockGetres. 4 bytes padding data from kernel stack are copied to user space incorrectly and leaked.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-41802?
CVE-2022-41802 is a vulnerability in the kernel subsystem within OpenHarmony-v3.1.4 and prior versions.
What is the severity of CVE-2022-41802?
The severity of CVE-2022-41802 is medium, with a severity value of 3.3.
How does CVE-2022-41802 affect OpenHarmony?
CVE-2022-41802 affects OpenHarmony versions 1.1.0 to 1.1.5, 3.0 to 3.0.6, and 3.1 to 3.1.4.
What is the vulnerability in CVE-2022-41802?
CVE-2022-41802 is a kernel stack overflow vulnerability in the OpenHarmony kernel_liteos_a subsystem when calling SysClockGetres.
Is there a fix available for CVE-2022-41802?
Currently, there is no fix available for CVE-2022-41802. It is recommended to follow the security advisory from OpenHarmony for updates.