← Back to CVE List
Vulnerability Intelligence Report
Mali GPU Kernel Driver exposes sensitive data from freed memory

CVE-2023-4272

A local non-privileged user can make GPU processing operations that expose sensitive data from previously freed memory.

No Active Exploit Signals
CVSS Base Score
5.5
MEDIUM
Exploitability:1.9
Impact Score:3.6
EPSS Probability:0.34%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-1251 ↗CWE-1251 Mirrored Regions with Different Values
CWE-200 ↗CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

Affected Products & Versions

Vendor Product Affected Versions
Arm Ltd Midgard GPU Kernel Driver r8p0 <= r32p0 (affected)
Arm Ltd Bifrost GPU Kernel Driver r0p0 < r42p0 (affected)
Arm Ltd Valhall GPU Kernel Driver r19p0 < r42p0 (affected)
Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver r41p0 < r42p0 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.340%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityArm Limited · Open Source · UK
Reserved2023-08-09T12:41:30
Published2023-11-07T15:18:59
Patch Date2023-11-07
Last Updated2024-09-04T19:35:16

LINK COPIED TO CLIPBOARD