PT-2024-2529 · Arm · Arm Valhall Gpu Kernel Driver+3
Published
2024-03-04
·
Updated
2025-03-27
·
CVE-2023-6143
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Arm Ltd Midgard GPU Kernel Driver versions r13p0 through r32p0
Arm Ltd Bifrost GPU Kernel Driver versions r1p0 through r18p0
Arm Ltd Valhall GPU Kernel Driver versions r37p0 through r46p0
Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver versions r41p0 through r46p0
Description
The issue is related to a Use After Free vulnerability in the Arm Ltd GPU Kernel Drivers, which allows a local non-privileged user to exploit a software race condition and perform improper memory processing operations. This can occur when the system's memory is carefully prepared by the user and the system is under heavy load. The vulnerability is associated with synchronization errors when using shared resources.
Recommendations
For Arm Ltd Midgard GPU Kernel Driver versions r13p0 through r32p0, update to a version outside of this range to resolve the issue.
For Arm Ltd Bifrost GPU Kernel Driver versions r1p0 through r18p0, update to a version outside of this range to resolve the issue.
For Arm Ltd Valhall GPU Kernel Driver versions r37p0 through r46p0, update to a version outside of this range to resolve the issue.
For Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver versions r41p0 through r46p0, update to a version outside of this range to resolve the issue.
As a temporary workaround, consider restricting access to shared resources to minimize the risk of exploitation.
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Arm 5Th Gen Gpu Architecture Kernel Driver
Arm Bifrost Gpu Kernel Driver
Arm Ltd Midgard Gpu Kernel Driver
Arm Valhall Gpu Kernel Driver