PT-2024-14821 · Arm · Arm Mali Gpu Kernel Driver+3

Published

2024-02-05

·

Updated

2024-02-13

·

CVE-2023-5643

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Arm Ltd Bifrost GPU Kernel Driver versions r41p0 through r45p0 Arm Ltd Valhall GPU Kernel Driver versions r41p0 through r45p0 Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver versions r41p0 through r45p0
Description The issue allows a local non-privileged user to make improper GPU memory processing operations. Depending on the configuration of the Mali GPU Kernel Driver, and if the system’s memory is carefully prepared by the user, then this in turn could write to memory outside of buffer bounds.
Recommendations For Arm Ltd Bifrost GPU Kernel Driver versions r41p0 through r45p0, update to a version outside of the affected range. For Arm Ltd Valhall GPU Kernel Driver versions r41p0 through r45p0, update to a version outside of the affected range. For Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver versions r41p0 through r45p0, update to a version outside of the affected range. As a temporary workaround, consider restricting access to the GPU memory processing operations until a patch is available.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ASB-A-308188986
CVE-2023-5643

Affected Products

Arm 5Th Gen Gpu Architecture Kernel Driver
Arm Bifrost Gpu Kernel Driver
Arm Mali Gpu Kernel Driver
Valhall Gpu Kernel Driver