← Back to CVE List
Vulnerability Intelligence Report
Arm Mali GPU Kernel Driver Information Disclosure Vulnerability

CVE-2023-26083

Memory leak vulnerability in Mali GPU Kernel Driver in Midgard GPU Kernel Driver all versions from r6p0 - r32p0, Bifrost GPU Kernel Driver all versions from r0p0 - r42p0, Valhall GPU Kernel Driver all versions from r19p0 - r42p0, and Avalon GPU Kernel Driver all versions from r41p0 - r42p0 allows a non-privileged user to make valid GPU processing operations that expose sensitive kernel metadata.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
3.3
LOW
Exploitability:1.9
Impact Score:1.5
EPSS Probability:1.42%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-401 ↗CWE-401 Missing Release of Memory after Effective Lifetime

Affected Products & Versions

Vendor Product Affected Versions
arm 5th_gen_gpu_architecture_kernel_driver all
arm bifrost_gpu_kernel_driver all
arm midgard_gpu_kernel_driver all
arm valhall_gpu_kernel_driver all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
1.417%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2023-02-20T00:00:00
Published2023-04-06T00:00:00
Last Updated2025-10-21T23:15:20

LINK COPIED TO CLIPBOARD