CVE-2022-45126: Kernel subsystem in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGettime.
Published Jan 9, 2023
·Updated
Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernelliteosa has a kernel stack overflow vulnerability when call SysClockGettime. 4 bytes padding data from kernel stack are copied to user space incorrectly and leaked.
Affected Software
5 affected components
OpenHarmony OpenHarmony>=1.1.0<=1.1.5
OpenHarmony OpenHarmony>=3.0<=3.0.6
OpenHarmony OpenHarmony>=3.1.0<=3.1.4
Openatom Openharmony>=1.1.0<=1.1.5
Openatom Openharmony>=3.0<=3.0.6
Event History
Jan 9, 2023
CVE Published
via MITRE·02:22 AM
Data Sourced
via MITRE·02:22 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-45126?
CVE-2022-45126 is a kernel stack overflow vulnerability in the OpenHarmony-v3.1.4 and prior versions of kernel_liteos_a when calling SysClockGettime.
2
What is the severity of CVE-2022-45126?
CVE-2022-45126 has a severity rating of 7.8 (high).
3
Which software versions are affected by CVE-2022-45126?
OpenHarmony versions 1.1.0 to 1.1.5, 3.0 to 3.0.6, and 3.1.0 to 3.1.4 are affected by CVE-2022-45126.
4
What is the CWE ID for CVE-2022-45126?
CVE-2022-45126 is associated with CWE IDs 787 and 120.
5
How can CVE-2022-45126 be fixed?
To fix CVE-2022-45126, update to the latest version of OpenHarmony that includes the necessary security patches.