Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8539-9wvx-7jmj

Опубликовано: 09 янв. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGettime. 4 bytes padding data from kernel stack are copied to user space incorrectly and leaked.

Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGettime. 4 bytes padding data from kernel stack are copied to user space incorrectly and leaked.

EPSS

Процентиль: 19%
0.0006
Низкий

7.8 High

CVSS3

Дефекты

CWE-120
CWE-787

Связанные уязвимости

CVSS3: 4
nvd
около 3 лет назад

Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGettime. 4 bytes padding data from kernel stack are copied to user space incorrectly and leaked.

EPSS

Процентиль: 19%
0.0006
Низкий

7.8 High

CVSS3

Дефекты

CWE-120
CWE-787