CVE-2022-48297: High severity emui 5.0 vulnerability
Published Feb 9, 2023
·Updated
The geofencing kernel code has a vulnerability of not verifying the length of the input data. Successful exploitation of this vulnerability may cause out-of-bounds memory access.
Affected Software
3 affected components
Huawei Emui=12.0.1
Huawei Harmonyos=2.0
Huawei Harmonyos=3.0.0
Remediation
Event History
Feb 9, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-48297?
CVE-2022-48297 is classified as a medium severity vulnerability due to the potential for out-of-bounds memory access.
2
How do I fix CVE-2022-48297?
To fix CVE-2022-48297, ensure that the latest security updates for Huawei Emui version 12.0.1 and HarmonyOS versions 2.0 and 3.0.0 are applied.
3
What could happen if CVE-2022-48297 is exploited?
Exploitation of CVE-2022-48297 could lead to unintended memory corruption and potential system instability.
4
Which software versions are affected by CVE-2022-48297?
CVE-2022-48297 affects Huawei Emui 12.0.1 and HarmonyOS versions 2.0 and 3.0.0.
5
Is there any workaround for CVE-2022-48297 before applying the fix?
Currently, there are no known workarounds for CVE-2022-48297, so applying security patches is the recommended action.