CVE-2025-25278: liteos_a has a race condition vulnerability
Published Aug 11, 2025
·Updated
in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through race condition.
Affected Software
3 affected components
OpenHarmony OpenHarmony<=5.0.3
LiteOS LiteOS A
Openatom Openharmony<=5.0.3
Event History
Aug 11, 2025
CVE Published
via MITRE·02:36 AM
Data Sourced
via MITRE·02:36 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-25278?
CVE-2025-25278 has been classified as critical due to its potential for arbitrary code execution.
2
How do I fix CVE-2025-25278?
To address CVE-2025-25278, update to OpenHarmony version 5.0.4 or later, which includes the necessary security patches.
3
What products are affected by CVE-2025-25278?
CVE-2025-25278 affects OpenHarmony versions 5.0.3 and earlier as well as LiteOS A.
4
What type of vulnerability is CVE-2025-25278?
CVE-2025-25278 is a race condition vulnerability that allows for arbitrary code execution by a local attacker.
5
Can CVE-2025-25278 be exploited remotely?
No, CVE-2025-25278 requires local access to exploit the vulnerability.