Overview
- Description
- The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishandled. This affects Bifrost r0p0 through r38p1, and r39p0; Valhall r19p0 through r38p1, and r39p0; and Midgard r4p0 through r32p0.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
Known exploits
Data from CISA
- Vulnerability name
- Arm Mali GPU Kernel Driver Use-After-Free Vulnerability
- Exploit added on
- Mar 30, 2023
- Exploit action due
- Apr 20, 2023
- Required action
- Apply updates per vendor instructions.
Weaknesses
- nvd@nist.gov
- CWE-416
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:arm:bifrost_gpu_kernel_driver:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "822BBE31-6AD6-4C5A-A01C-0994215DD167", "versionEndIncluding": "r38p1", "versionStartIncluding": "r0p0" }, { "criteria": "cpe:2.3:a:arm:bifrost_gpu_kernel_driver:r39p0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C5628A8D-18D5-4A0F-A474-13024A73F17F" }, { "criteria": "cpe:2.3:a:arm:midgard_gpu_kernel_driver:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A1AB50D5-AAC9-473D-B450-8275CB7E1676", "versionEndIncluding": "r31p0", "versionStartIncluding": "r4p0" }, { "criteria": "cpe:2.3:a:arm:valhall_gpu_kernel_driver:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3DC17807-E62F-4601-BF21-E64DFA7AA3ED", "versionEndIncluding": "r38p1", "versionStartIncluding": "r19p0" }, { "criteria": "cpe:2.3:a:arm:valhall_gpu_kernel_driver:r39p0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "05471A20-62BC-4626-BE77-0902B098834E" } ], "operator": "OR" } ] } ]