CVE-2025-27241: multimedia_av_codec has a NULL pointer dereference vulnerability
Published May 6, 2025
·Updated
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference.
Affected Software
3 affected components
OpenHarmony OpenHarmony<5.0.3
OpenHarmony multimedia_av_codec<5.0.3
Openatom Openharmony<=5.0.3
Event History
May 6, 2025
CVE Published
via MITRE·09:03 AM
Data Sourced
via MITRE·09:03 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-27241?
CVE-2025-27241 is classified as a denial of service vulnerability that can be exploited by local attackers.
2
How do I fix CVE-2025-27241?
To mitigate CVE-2025-27241, update OpenHarmony to version 5.0.4 or later.
3
Who is affected by CVE-2025-27241?
CVE-2025-27241 affects OpenHarmony v5.0.3 and earlier versions, including the multimedia_av_codec component.
4
What type of vulnerability is CVE-2025-27241?
CVE-2025-27241 is a local denial of service vulnerability caused by NULL pointer dereference.
5
Can CVE-2025-27241 be exploited remotely?
No, CVE-2025-27241 can only be exploited locally by an attacker with access to the system.