Executive brief
A vulnerability in the OpenHarmony operating system allows a local user to cause a denial-of-service (DoS) condition. OpenHarmony is an open-source operating system designed for smart devices. An exploit could lead to system instability or crashes, temporarily disrupting the availability of the device for its users.
Technical details
A signal handler race condition (CWE-364) exists in OpenHarmony v6.0 and earlier versions. This vulnerability allows a local attacker with low privileges to trigger a race condition within signal handling logic, leading to a denial-of-service (DoS) state. The attack does not require user interaction but does require local access to the affected system. Successful exploitation results in a loss of availability for the impacted component or system. Users are advised to refer to the OpenHarmony security disclosure for patch information.
Affected products
- OpenHarmony OpenHarmony v6.0 and prior versions
Timeline
- 2026-05-19: disclosed: Initial publication of the CVE record