CVE-2025-53185Use After Free in Huawei Emui

CWE-416Use After Free4 documents4 sources
Severity
5.5MEDIUMNVD
CNA6.6
EPSS
0.0%
top 96.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 7

Description

Virtual address reuse issue in the memory management module, which can be exploited by non-privileged users to access released memory Impact: Successful exploitation of this vulnerability may affect service integrity.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

CVEListV5huawei/emui14.0.0
NVDhuawei/emui14.0.0
CVEListV5huawei/harmonyos4.0.0, 4.2.0+1
NVDhuawei/harmonyos4.0.0, 4.2.0+1

🔴Vulnerability Details

2
GHSA
GHSA-h8vq-57c7-9jv6: Virtual address reuse issue in the memory management module, which can be exploited by non-privileged users to access released memory Impact: Successf2025-07-07
CVEList
CVE-2025-53185: Virtual address reuse issue in the memory management module, which can be exploited by non-privileged users to access released memory Impact: Successf2025-07-07

📋Vendor Advisories

1
Microsoft
smb: client: fix NULL ptr deref in crypto_aead_setkey()2024-12-10
CVE-2025-53185 — Use After Free in Huawei Emui | cvebase