PT-2023-5889 · Arm · Mali Gpu Driver

Published

2023-10-02

·

Updated

2025-03-07

·

CVE-2023-34970

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Mali GPU driver (affected versions not specified)
Description The issue is related to improper GPU processing operations that can be performed by a local non-privileged user, potentially allowing access to limited areas outside of buffer bounds or exploiting a software race condition. This could grant access to already freed memory if the system's memory is carefully prepared. The vulnerability is also associated with synchronization errors when using shared resources in the Mali GPU driver based on Arm and Valhall architectures, which can lead to incorrect processing operations.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Memory Corruption

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ASB-A-287624919
BDU:2023-06582
CVE-2023-34970

Affected Products

Mali Gpu Driver