Vulnerability Intelligence Report
Mali GPU Kernel Driver Allows Improper GPU Memory Processing Operations
CVE-2023-4211
A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory.
CISA KEV
SSVC: Active Exploitation
CVSS Base Score
5.5
MEDIUM
Exploitability:1.9
Impact Score:3.6
EPSS Probability:1.36%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-416 ↗CWE-416 Use after free
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Arm Ltd | Midgard GPU Kernel Driver | r12p0 <= r32p0 (affected) |
| Arm Ltd | Bifrost GPU Kernel Driver | r0p0 <= r42p0 (affected) |
| Arm Ltd | Valhall GPU Kernel Driver | r19p0 <= r42p0 (affected) |
| Arm Ltd | Arm 5th Gen GPU Architecture Kernel Driver | r41p0 <= r42p0 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Arm Limited · Open Source · UK |
| Reserved | 2023-08-07T15:24:51 |
| Published | 2023-10-01T17:00:27 |
| Patch Date | 2023-10-01 |
| Last Updated | 2025-10-21T23:05:36 |
Community Chatter & Buzz