« Volver al listado

CVE-2021-22466

Estado: ModificadaMedia (5.5)—

Un componente de HarmonyOS presenta una vulnerabilidad de Uso de Memoria previamente Liberada. Unos atacantes locales pueden explotar esta vulnerabilidad para causar un bloqueo del kernel

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-22466",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.1,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@huawei.com",
      "affectedData": [
        {
          "vendor": "Huawei",
          "product": "HarmonyOS",
          "versions": [
            {
              "status": "affected",
              "version": "2.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-10-28T13:15:09.493",
  "references": [
    {
      "url": "https://device.harmonyos.com/cn/docs/security/update/security-bulletins-202107-0000001123874808",
      "tags": [
        "Not Applicable",
        "Vendor Advisory"
      ],
      "source": "psirt@huawei.com"
    },
    {
      "url": "https://device.harmonyos.com/cn/docs/security/update/security-bulletins-202107-0000001123874808",
      "tags": [
        "Not Applicable",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-416"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A component of the HarmonyOS has a Use After Free vulnerability. Local attackers may exploit this vulnerability to cause kernel crash."
    },
    {
      "lang": "es",
      "value": "Un componente de HarmonyOS presenta una vulnerabilidad de Uso de Memoria previamente Liberada. Unos atacantes locales pueden explotar esta vulnerabilidad para causar un bloqueo del kernel"
    }
  ],
  "lastModified": "2026-06-17T03:37:16.620",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:huawei:harmonyos:2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3AD62E8B-CB4B-43A6-98E8-09A8A1A3505B"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@huawei.com"
}