CVE-2025-0304: Liteos_a has an use after free vulnerability
Published Feb 7, 2025
·Updated
in OpenHarmony v4.1.2 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after free.
Affected Software
2 affected components
OpenHarmony OpenHarmony<4.1.2
Openatom Openharmony>=4.1.0<=4.1.2
Event History
Feb 7, 2025
CVE Published
via MITRE·09:21 AM
Data Sourced
via MITRE·09:21 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-0304?
CVE-2025-0304 is considered a high severity vulnerability due to the potential for privilege escalation and sensitive information leakage.
2
How do I fix CVE-2025-0304?
To fix CVE-2025-0304, update OpenHarmony to version 4.1.3 or later, where the vulnerability is addressed.
3
Who is affected by CVE-2025-0304?
CVE-2025-0304 affects all users of OpenHarmony versions up to 4.1.2.
4
What type of vulnerability is CVE-2025-0304?
CVE-2025-0304 is a use-after-free vulnerability that enables local attackers to escalate privileges.
5
What can an attacker achieve with CVE-2025-0304?
An attacker exploiting CVE-2025-0304 can gain root privileges and potentially leak sensitive information.