Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysTimerGettime. 4 bytes padding data from kernel stack are copied to user space incorrectly and leaked.
| Software | From | Fixed in |
|---|---|---|
| openharmony / openharmony | 3.1.0 | 3.1.4.x |
| openatom / openharmony | 3.0 | 3.0.6.x |
| openatom / openharmony | 1.1.0 | 1.1.5.x |