PT-2023-4577 · Arm · Arm Bifrost Gpu Userspace Driver+3

CVE-2023-32804

·

Publicado

2023-08-25

·

Atualizado

2023-12-07

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Arm Ltd Midgard GPU Userspace Driver versions r0p0 through r32p0 Arm Ltd Bifrost GPU Userspace Driver versions r0p0 through r44p0 Arm Ltd Valhall GPU Userspace Driver versions r19p0 through r44p0 Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver versions r41p0 through r44p0
Description The issue is an Out-of-bounds Write vulnerability in Arm Ltd GPU Userspace Drivers, allowing a local non-privileged user to write a constant pattern to a limited amount of memory not allocated by the user space driver. This can potentially allow an attacker to elevate their privileges.
Recommendations For Arm Ltd Midgard GPU Userspace Driver versions r0p0 through r32p0, update to a version outside of this range to resolve the issue. For Arm Ltd Bifrost GPU Userspace Driver versions r0p0 through r44p0, update to a version outside of this range to resolve the issue. For Arm Ltd Valhall GPU Userspace Driver versions r19p0 through r44p0, update to a version outside of this range to resolve the issue. For Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver versions r41p0 through r44p0, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting access to the affected drivers until a patch is available.

Correção

Buffer Overflow

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ASB-A-272772567
BDU:2023-04984
CVE-2023-32804

Produtos afetados

Arm 5Th Gen Gpu Architecture Userspace Driver
Arm Bifrost Gpu Userspace Driver
Midgard Gpu Userspace Driver
Valhall Gpu Userspace Driver