Use After Free Vulnerability in Arm Ltd Bifrost GPU Kernel Driver
CVE-2023-5249
7HIGH
Key Information:
- Vendor
- Arm Ltd
- Status
- Bifrost Gpu Kernel Driver
- Valhall Gpu Kernel Driver
- Vendor
- CVE Published:
- 5 February 2024
Summary
The vulnerability in Arm Ltd Bifrost and Valhall GPU Kernel Drivers arises from a Use After Free issue that allows a local non-privileged user to manipulate memory processing through a software race condition. By carefully preparing the system’s memory, an attacker could exploit this flaw, leading to potential unauthorized actions within the driver operation. This vulnerability affects specific versions of the Bifrost GPU Kernel Driver (from r35p0 to r40p0) and the Valhall GPU Kernel Driver (also from r35p0 to r40p0).
Affected Version(s)
Bifrost GPU Kernel Driver r35p0
Valhall GPU Kernel Driver r35p0
References
CVSS V3.1
Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved