CVE-2022-43662: Kernel subsystem in kernel_liteos_a has a kernel stack overflow vulnerability when call SysTimerGettime.
Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernelliteosa has a kernel stack overflow vulnerability when call SysTimerGettime. 4 bytes padding data from kernel stack are copied to user space incorrectly and leaked.
Affected Software
Event History
Frequently Asked Questions
What is vulnerability CVE-2022-43662?
Vulnerability CVE-2022-43662 is a kernel stack overflow vulnerability in the OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a.
How severe is vulnerability CVE-2022-43662?
Vulnerability CVE-2022-43662 has a severity rating of 7.8 (high severity).
What is the affected software for vulnerability CVE-2022-43662?
The affected software for vulnerability CVE-2022-43662 includes OpenHarmony versions 1.1.0 to 1.1.5, 3.0 to 3.0.6, and 3.1.0 to 3.1.4.
How can I fix vulnerability CVE-2022-43662?
To fix vulnerability CVE-2022-43662, update OpenHarmony to a version that is not affected by the vulnerability.
Where can I find more information about vulnerability CVE-2022-43662?
More information about vulnerability CVE-2022-43662 can be found at the following link: [link](https://gitee.com/openharmony/security/blob/master/en/security-disclosure/2022/2022-12.md)