← Back to CVE List
Vulnerability Intelligence Report
Mali GPU Kernel Driver Allows Improper GPU Memory Processing Operations

CVE-2023-33200

A local non-privileged user can make improper GPU processing operations to exploit a software race condition. If the system’s memory is carefully prepared by the user, then this in turn could give them access to already freed memory.

No Active Exploit Signals
CVSS Base Score
4.7
MEDIUM
Exploitability:1.1
Impact Score:3.6
EPSS Probability:0.29%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-416 ↗CWE-416 Use after free

Affected Products & Versions

Vendor Product Affected Versions
Arm Ltd Bifrost GPU Kernel Driver r17p0 < r44p1 (affected)
Arm Ltd Valhall GPU Kernel Driver r19p0 < r44p1 (affected)
Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver r41p0 < r44p1 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.292%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityArm Limited · Open Source · UK
Reserved2023-05-18T06:53:10
Published2023-10-03T16:39:10
Patch Date2023-10-01
Last Updated2025-03-07T18:29:58

LINK COPIED TO CLIPBOARD