CVE-2025-24304: arkcompiler_ets_runtime has an out-of-bounds write vulnerability
Published Apr 7, 2025
·Updated
in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds write.
Affected Software
2 affected components
OpenHarmony OpenHarmony<5.0.2
Openatom Openharmony<=5.0.2
Event History
Apr 7, 2025
CVE Published
via MITRE·02:35 AM
Data Sourced
via MITRE·02:35 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-24304?
CVE-2025-24304 has been rated as a high severity vulnerability due to its potential to cause denial of service through out-of-bounds writes.
2
How do I fix CVE-2025-24304?
To address CVE-2025-24304, upgrade to OpenHarmony version 5.0.3 or later, which includes fixes for this vulnerability.
3
What versions of OpenHarmony are affected by CVE-2025-24304?
OpenHarmony versions 5.0.2 and earlier are affected by CVE-2025-24304.
4
Who can exploit CVE-2025-24304?
CVE-2025-24304 can be exploited by a local attacker with access to the affected OpenHarmony system.
5
What type of attack does CVE-2025-24304 facilitate?
CVE-2025-24304 facilitates a denial-of-service attack through an out-of-bounds write, potentially disrupting service availability.