Mali GPU Kernel Driver allows improper GPU memory processing operations
CVE-2023-5643
7.8HIGH
Key Information:
- Vendor
- Arm
- Vendor
- CVE Published:
- 5 February 2024
Summary
The vulnerability identified allows a local non-privileged user to exploit improper GPU memory processing operations within the Bifrost, Valhall, and 5th Gen GPU Kernel Drivers developed by Arm Ltd. If the Mali GPU Kernel Driver is misconfigured and memory is prepared appropriately by the user, there exists a risk of writing to memory segments outside of the designated buffer bounds, potentially leading to unpredictable behavior or system instability. This issue spans multiple versions of the affected drivers, necessitating careful attention to system configurations and updates.
Affected Version(s)
Arm 5th Gen GPU Architecture Kernel Driver r41p0
Bifrost GPU Kernel Driver r41p0
Valhall GPU Kernel Driver r41p0
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved