Local Denial of Service Vulnerability in OpenHarmony v5.0.3 and Prior Versions
CVE-2025-25217

5.5MEDIUM

Key Information:

Vendor
CVE Published:
8 June 2025

What is CVE-2025-25217?

OpenHarmony versions v5.0.3 and earlier contain a vulnerability that allows local attackers to cause a Denial of Service (DoS) condition by exploiting a NULL pointer dereference. This flaw could lead to unexpected behavior in the system, potentially crashing the application or disrupting service. It highlights the importance of robust input validation and error handling to mitigate such vulnerabilities in software.

Affected Version(s)

OpenHarmony v5.0.1

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.