CVE-2022-42464
Last modified
CVE-2022-42464 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. OpenHarmony-v3.1.2 and prior versions, 3.0.6 and prior versions have a Kernel memory pool override vulnerability in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
OpenHarmony-v3.1.2 and prior versions, 3.0.6 and prior versions have a Kernel memory pool override vulnerability in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged process run on the device could disclose sensitive information including kernel pointer, which could be used in further attacks. The processes with system user UID run on the device would be able to mmap memory pools used by kernel and override them which could be used to gain kernel code execution on the device, gain root privileges, or cause device reboot.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openharmony | Openharmony | >= 3.0, <= 3.0.6 |
| Openharmony | Openharmony | >= 3.1, <= 3.1.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-42464?
How severe is CVE-2022-42464?
How do I fix CVE-2022-42464?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-42459Auth. WordPress Options Change vulnerability in Image Hover …7.2
- CVE-2022-4246A vulnerability classified as problematic has been found in …7.5
- CVE-2022-42460Broken Access Control vulnerability leading to Stored Cross-…5.4
- CVE-2022-42461Broken Access Control vulnerability in miniOrange's Google A…8.8
- CVE-2022-42462Auth. Stored Cross-Site Scripting (XSS) vulnerability in Ade…4.8
- CVE-2022-42463OpenHarmony-v3.1.2 and prior versions have an authenication …8.8
- CVE-2022-42465Improper access control in kernel mode driver for the Intel(…6.7
- CVE-2022-42466Prior to 2.0.0-M9, it was possible for an end-user to set th…6.1
- CVE-2022-42467When running in prototype mode, the h2 webconsole module (ac…5.3
- CVE-2022-42468Apache Flume versions 1.4.0 through 1.10.1 are vulnerable to…9.8
- CVE-2022-42469A permissive list of allowed inputs vulnerability [CWE-183] …4.3
- CVE-2022-4247A vulnerability classified as critical was found in Movie Ti…9.8
Are you affected by CVE-2022-42464?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
