Vulnerability Details CVE-2023-22436
The kernel subsystem function check_permission_for_set_tokenid within OpenHarmony-v3.1.5 and prior versions has an
UAF vulnerability which local attackers can exploit this vulnerability to escalate the privilege to root.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 8.8%
CVSS Severity
CVSS v3 Score 7.8
Products affected by CVE-2023-22436
-
cpe:2.3:o:openatom:openharmony:3.1
-
cpe:2.3:o:openatom:openharmony:3.1.1
-
cpe:2.3:o:openatom:openharmony:3.1.2
-
cpe:2.3:o:openatom:openharmony:3.1.3
-
cpe:2.3:o:openatom:openharmony:3.1.4
-
cpe:2.3:o:openatom:openharmony:3.1.5