CVE-2024-47404: Liteos_a has a double free vulnerability
Published Nov 5, 2024
·Updated
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through double free.
Affected Software
1 affected component
Openatom Openharmony>=4.0<=4.1
Event History
Nov 5, 2024
CVE Published
via MITRE·08:01 AM
Data Sourced
via MITRE·08:01 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-47404?
CVE-2024-47404 is considered a high severity vulnerability due to its potential to escalate privileges to root.
2
How do I fix CVE-2024-47404?
To mitigate CVE-2024-47404, update OpenHarmony to version 4.1.1 or later where the vulnerability has been patched.
3
Who is affected by CVE-2024-47404?
CVE-2024-47404 affects all installations of OpenHarmony version 4.1.0 and earlier.
4
What type of vulnerability is CVE-2024-47404?
CVE-2024-47404 is a local privilege escalation vulnerability that can lead to sensitive information leaks.
5
Can CVE-2024-47404 be exploited remotely?
No, CVE-2024-47404 requires local access to the system for exploitation.