Mali GPU Kernel Driver allows improper GPU memory processing operations
CVE-2023-4295
7.8HIGH
Key Information:
- Vendor
- Arm Ltd
- Status
- Valhall Gpu Kernel Driver
- Arm 5th Gen Gpu Architecture Kernel Driver
- Vendor
- CVE Published:
- 7 November 2023
Summary
A local non-privileged user can exploit a flaw in the Arm Mali GPU driver, allowing them to perform improper GPU memory processing operations. This vulnerability enables the user to access memory that has already been freed, potentially leading to unintended information disclosure and system instability. Proper memory management practices are crucial in mitigating this risk.
Affected Version(s)
Arm 5th Gen GPU Architecture Kernel Driver r41p0
Valhall GPU Kernel Driver r29p0
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jann Horn at Google