PT-2023-4577 · Arm · Arm Bifrost Gpu Userspace Driver+3
CVE-2023-32804
·
Publicado
2023-08-25
·
Atualizado
2023-12-07
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Arm Ltd Midgard GPU Userspace Driver versions r0p0 through r32p0
Arm Ltd Bifrost GPU Userspace Driver versions r0p0 through r44p0
Arm Ltd Valhall GPU Userspace Driver versions r19p0 through r44p0
Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver versions r41p0 through r44p0
Description
The issue is an Out-of-bounds Write vulnerability in Arm Ltd GPU Userspace Drivers, allowing a local non-privileged user to write a constant pattern to a limited amount of memory not allocated by the user space driver. This can potentially allow an attacker to elevate their privileges.
Recommendations
For Arm Ltd Midgard GPU Userspace Driver versions r0p0 through r32p0, update to a version outside of this range to resolve the issue.
For Arm Ltd Bifrost GPU Userspace Driver versions r0p0 through r44p0, update to a version outside of this range to resolve the issue.
For Arm Ltd Valhall GPU Userspace Driver versions r19p0 through r44p0, update to a version outside of this range to resolve the issue.
For Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver versions r41p0 through r44p0, update to a version outside of this range to resolve the issue.
As a temporary workaround, consider restricting access to the affected drivers until a patch is available.
Correção
Buffer Overflow
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Arm 5Th Gen Gpu Architecture Userspace Driver
Arm Bifrost Gpu Userspace Driver
Midgard Gpu Userspace Driver
Valhall Gpu Userspace Driver