CVE-2025-26690: communication dsoftbus has a NULL pointer vulnerability
Published Aug 11, 2025
·Updated
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference.
Affected Software
2 affected components
OpenHarmony OpenHarmony<5.0.3
Openatom Openharmony<=5.0.3
Event History
Aug 11, 2025
CVE Published
via MITRE·02:55 AM
Data Sourced
via MITRE·02:55 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-26690?
CVE-2025-26690 has been classified as a medium severity vulnerability due to its potential to cause a denial of service through NULL pointer dereference.
2
How do I fix CVE-2025-26690?
To fix CVE-2025-26690, upgrade to OpenHarmony v5.0.4 or later, which addresses this vulnerability.
3
Who is affected by CVE-2025-26690?
CVE-2025-26690 affects all versions of OpenHarmony up to and including v5.0.3.
4
What type of vulnerability is CVE-2025-26690?
CVE-2025-26690 is a local denial of service vulnerability caused by a NULL pointer dereference.
5
Can CVE-2025-26690 be exploited remotely?
No, CVE-2025-26690 requires local access to the affected system to exploit the vulnerability.