Mali GPU Kernel Driver allows improper GPU memory processing operations
CVE-2023-4295
7.8HIGH
Key Information:
- Vendor
Arm
- Vendor
- CVE Published:
- 7 November 2023
What is CVE-2023-4295?
A local non-privileged user can exploit a flaw in the Arm Mali GPU driver, allowing them to perform improper GPU memory processing operations. This vulnerability enables the user to access memory that has already been freed, potentially leading to unintended information disclosure and system instability. Proper memory management practices are crucial in mitigating this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Arm 5th Gen GPU Architecture Kernel Driver r41p0
Valhall GPU Kernel Driver r29p0
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jann Horn at Google