CVE-2023-22436: The kernel subsystem function check_permission_for_set_tokenid has an UAF vulnerability.
Published Mar 10, 2023
·Updated
The kernel subsystem function checkpermissionforsettokenid within OpenHarmony-v3.1.5 and prior versions has an
UAF vulnerability which local attackers can exploit this vulnerability to escalate the privilege to root.
Affected Software
2 affected components
OpenHarmony OpenHarmony>=3.1<=3.1.5
Openatom Openharmony>=3.1<=3.1.5
Event History
Mar 10, 2023
CVE Published
via MITRE·10:44 AM
Data Sourced
via MITRE·10:44 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-22436.
2
What is the severity of CVE-2023-22436?
The severity of CVE-2023-22436 is high.
3
What is the affected software of CVE-2023-22436?
OpenHarmony versions 3.1.5 and prior are affected by CVE-2023-22436.
4
What is the impact of CVE-2023-22436?
CVE-2023-22436 allows local attackers to exploit a use-after-free (UAF) vulnerability, leading to privilege escalation to root.
5
Is there a fix available for CVE-2023-22436?
At the time of this advisory, there is no known fix available for CVE-2023-22436. It is recommended to follow the provided reference for further updates and mitigation measures.