Use After Free Vulnerability in Arm Ltd Bifrost GPU Kernel Driver
CVE-2023-5249

7HIGH

Key Information:

Vendor
Arm Ltd
Status
Bifrost Gpu Kernel Driver
Valhall Gpu Kernel Driver
Vendor
CVE Published:
5 February 2024

Summary

The vulnerability in Arm Ltd Bifrost and Valhall GPU Kernel Drivers arises from a Use After Free issue that allows a local non-privileged user to manipulate memory processing through a software race condition. By carefully preparing the system’s memory, an attacker could exploit this flaw, leading to potential unauthorized actions within the driver operation. This vulnerability affects specific versions of the Bifrost GPU Kernel Driver (from r35p0 to r40p0) and the Valhall GPU Kernel Driver (also from r35p0 to r40p0).

Affected Version(s)

Bifrost GPU Kernel Driver r35p0

Valhall GPU Kernel Driver r35p0

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.