Mali GPU Kernel Driver allows improper GPU memory processing operations
CVE-2023-4295

7.8HIGH

Key Information:

Vendor
Arm Ltd
Status
Valhall Gpu Kernel Driver
Arm 5th Gen Gpu Architecture Kernel Driver
Vendor
CVE Published:
7 November 2023

Summary

A local non-privileged user can exploit a flaw in the Arm Mali GPU driver, allowing them to perform improper GPU memory processing operations. This vulnerability enables the user to access memory that has already been freed, potentially leading to unintended information disclosure and system instability. Proper memory management practices are crucial in mitigating this risk.

Affected Version(s)

Arm 5th Gen GPU Architecture Kernel Driver r41p0

Valhall GPU Kernel Driver r29p0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jann Horn at Google
.