CVE-2025-25052: arkcompiler_ets_runtime has a buffer overflow vulnerability
Published May 6, 2025
·Updated
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through buffer overflow.
Affected Software
3 affected components
OpenHarmony OpenHarmony<5.0.3
Openatom Openharmony<=4.1
Openatom Openharmony>=5.0<=5.0.3
Event History
May 6, 2025
CVE Published
via MITRE·09:03 AM
Data Sourced
via MITRE·09:03 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-25052?
CVE-2025-25052 is classified as a high severity vulnerability due to the potential for a local attacker to cause a denial of service through buffer overflow.
2
How do I fix CVE-2025-25052?
To fix CVE-2025-25052, update OpenHarmony to version 5.0.4 or later.
3
What versions of OpenHarmony are affected by CVE-2025-25052?
OpenHarmony versions 5.0.3 and prior are affected by CVE-2025-25052.
4
Who can exploit CVE-2025-25052?
CVE-2025-25052 can be exploited by local attackers with access to the affected device.
5
What impact does CVE-2025-25052 have on systems?
CVE-2025-25052 can cause a denial of service, rendering the affected system unresponsive.