CVE-2026-25781: kernel_liteos_a has an out-of-bounds write vulnerability
Published May 19, 2026
·Updated
in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS and it cannot be recovered.
Affected Software
2 affected components
OpenHarmony OpenHarmony<=6.0
OpenHarmony kernel_liteos_a<=6.0
Event History
May 19, 2026
CVE Published
via MITRE·03:08 AM
Data Sourced
via MITRE·03:08 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-25781?
CVE-2026-25781 is a critical vulnerability that allows a local attacker to cause denial of service.
2
How do I fix CVE-2026-25781?
To mitigate CVE-2026-25781, update to OpenHarmony versions later than v6.0 which contain the necessary security patches.
3
What software is affected by CVE-2026-25781?
CVE-2026-25781 affects OpenHarmony OpenHarmony and kernel_liteos_a up to and including version 6.0.
4
Can CVE-2026-25781 cause system recovery issues?
Yes, exploiting CVE-2026-25781 can lead to denial of service that cannot be recovered without a system reboot.
5
Who is impacted by CVE-2026-25781?
Local attackers with access to systems running vulnerable versions of OpenHarmony are primarily impacted by CVE-2026-25781.