CVE-2025-24844: communication_dsoftbus has a missing release of memory vulnerability
Published Aug 11, 2025
·Updated
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory.
Affected Software
2 affected components
OpenHarmony OpenHarmony<5.0.3
Openatom Openharmony<=5.0.3
Event History
Aug 11, 2025
CVE Published
via MITRE·02:55 AM
Data Sourced
via MITRE·02:55 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-24844?
CVE-2025-24844 is considered a moderate severity vulnerability due to its potential to cause denial of service.
2
How do I fix CVE-2025-24844?
To fix CVE-2025-24844, upgrade to OpenHarmony version 5.0.4 or later where the memory release issue has been addressed.
3
Who is affected by CVE-2025-24844?
OpenHarmony v5.0.3 and prior versions are affected by CVE-2025-24844.
4
What type of attack does CVE-2025-24844 allow?
CVE-2025-24844 allows a local attacker to perform a denial of service (DoS) attack due to missing memory release.
5
When was CVE-2025-24844 disclosed?
CVE-2025-24844 was disclosed in 2025, along with details on the vulnerability's impact.