← Back to CVE List
Vulnerability Intelligence Report
Mali GPU Kernel Driver allows improper GPU memory processing operations

CVE-2023-4295

A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory.

No Active Exploit Signals
CVSS Base Score
7.8
HIGH
Exploitability:1.9
Impact Score:5.9
EPSS Probability:0.25%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-190 ↗CWE-190 Integer Overflow or Wraparound
CWE-416 ↗CWE-416 Use After Free

Affected Products & Versions

Vendor Product Affected Versions
Arm Ltd Valhall GPU Kernel Driver r29p0 < r43p0 (affected)
Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver r41p0 < r43p0 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.251%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityArm Limited · Open Source · UK
Reserved2023-08-10T14:44:40
Published2023-11-07T15:42:15
Patch Date2023-11-07
Last Updated2025-12-16T18:23:25

LINK COPIED TO CLIPBOARD