CVE-2023-22436: Openatom Openharmony
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
The kernel subsystem function check_permission_for_set_tokenid within OpenHarmony-v3.1.5 and prior versions has an UAF vulnerability which local attackers can exploit this vulnerability to escalate the privilege to root.
Affected products
- Openatom Openharmony: from 3.1, up to and including 3.1.5
Published 2023-03-10. Last modified 2026-06-17.