CVE-2025-27248: ai_neural_network_runtime has a NULL pointer dereference vulnerability
Published May 6, 2025
·Updated
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference.
Affected Software
2 affected components
OpenHarmony OpenHarmony<5.0.3
Openatom Openharmony<=5.0.3
Event History
May 6, 2025
CVE Published
via MITRE·09:03 AM
Data Sourced
via MITRE·09:03 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-27248?
CVE-2025-27248 is considered a medium severity vulnerability due to its potential to cause a denial of service through NULL pointer dereference.
2
How do I fix CVE-2025-27248?
To mitigate CVE-2025-27248, users should upgrade to OpenHarmony v5.0.4 or later, where this vulnerability is addressed.
3
Who is affected by CVE-2025-27248?
CVE-2025-27248 affects all versions of OpenHarmony up to and including v5.0.3.
4
What type of attack does CVE-2025-27248 expose the system to?
CVE-2025-27248 exposes the system to a Denial of Service (DoS) attack through remote local exploitation.
5
Can CVE-2025-27248 be exploited remotely?
CVE-2025-27248 cannot be exploited remotely as it requires local access to the system for attack.