CVE-2025-25217: arkui_ace_enginehas a NULL pointer dereference vulnerability
Published Jun 8, 2025
·Updated
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference.
Affected Software
1 affected component
Openatom Openharmony<=5.0.3
Event History
Jun 8, 2025
CVE Published
via MITRE·11:46 AM
Data Sourced
via MITRE·11:46 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-25217?
CVE-2025-25217 is classified as a high severity vulnerability due to its potential to cause a denial of service.
2
How can I fix CVE-2025-25217?
To mitigate CVE-2025-25217, upgrade to OpenHarmony version 5.1.0 or later, which includes a patch for this issue.
3
What versions of OpenHarmony are affected by CVE-2025-25217?
CVE-2025-25217 affects OpenHarmony versions up to and including 5.0.3.
4
Who can exploit CVE-2025-25217?
CVE-2025-25217 can be exploited by a local attacker with limited access to the system.
5
What type of attack is possible due to CVE-2025-25217?
CVE-2025-25217 allows for a denial of service attack through a NULL pointer dereference.