CVE-2025-25218: third_party_mksh has a NULL pointer dereference vulnerability
Published May 6, 2025
·Updated
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference.
Affected Software
3 affected components
OpenHarmony OpenHarmony<=5.0.3
third_party_mksh mksh
Openatom Openharmony<=5.0.3
Event History
May 6, 2025
CVE Published
via MITRE·08:50 AM
Data Sourced
via MITRE·08:50 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-25218?
CVE-2025-25218 is classified as a denial-of-service vulnerability.
2
How does CVE-2025-25218 allow local attackers to cause a denial of service?
CVE-2025-25218 allows local attackers to cause a denial of service through a NULL pointer dereference.
3
Which versions of OpenHarmony are affected by CVE-2025-25218?
OpenHarmony versions up to and including 5.0.3 are affected by CVE-2025-25218.
4
What are the potential impacts of exploiting CVE-2025-25218?
Exploiting CVE-2025-25218 can lead to system instability and potential crashes.
5
Is there a patch available for CVE-2025-25218?
Patch information for CVE-2025-25218 needs to be checked from the official OpenHarmony security disclosures.