CVE-2024-21834: Arkui has a type confusion vulnerability
Published Apr 2, 2024
·Updated
in OpenHarmony v3.2.4 and prior versions allow a local attacker cause apps crash through type confusion.
Affected Software
1 affected component
Openatom Openharmony<=3.2.4
Event History
Apr 2, 2024
CVE Published
via MITRE·06:22 AM
Data Sourced
via MITRE·06:22 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-21834?
The severity of CVE-2024-21834 is classified as medium, as it allows local attackers to crash applications.
2
How do I fix CVE-2024-21834?
To fix CVE-2024-21834, upgrade to OpenHarmony version 3.2.5 or later.
3
What versions of OpenHarmony are affected by CVE-2024-21834?
CVE-2024-21834 affects OpenHarmony versions up to and including 3.2.4.
4
What type of attack does CVE-2024-21834 involve?
CVE-2024-21834 involves a local attacker exploiting type confusion to cause app crashes.
5
Can CVE-2024-21834 be exploited remotely?
No, CVE-2024-21834 can only be exploited by a local attacker with access to the system.