The kernel server has a vulnerability of not verifying the length of the data transferred in the user space.Successful exploitation of this vulnerability may cause out-of-bounds read in the kernel, which affects the device confidentiality and availability.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://consumer.huawei.com/en/support/bulletin/2022/10/ | vendor advisory |
https://device.harmonyos.com/en/docs/security/update/security-bulletins-phones-202210-0000001416095697 | vendor advisory |