CVE-2023-26083
Arm Mali GPU Kernel Driver Information Disclosure Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 28 April 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Memory leak vulnerability in Mali GPU Kernel Driver in Midgard GPU Kernel Driver all versions from r6p0 - r32p0, Bifrost GPU Kernel Driver all versions from r0p0 - r42p0, Valhall GPU Kernel Driver all versions from r19p0 - r42p0, and Avalon GPU Kernel Driver all versions from r41p0 - r42p0 allows a non-privileged user to make valid GPU processing operations that expose sensitive kernel metadata.
- CVSS 3.1
- 3.3 LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.22% probability · 67th percentile
- CISA KEV
- Listed 7 April 2023 · due 28 April 2023
- Weakness
- CWE-401
- Affected
- arm/5th gen gpu architecture kernel driver · arm/bifrost gpu kernel driver · arm/midgard gpu kernel driver · arm/valhall gpu kernel driver
- Source
- cve@mitre.org
CISA notes
Apply updates per vendor instructions. https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities; https://nvd.nist.gov/vuln/detail/CVE-2023-26083
References
- https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20VulnerabilitiesVendor Advisory
- https://www.cybersecurity-help.cz/vdb/SB2023033049Third Party Advisory
- https://www.cybersecurity-help.cz/vulnerabilities/74210/Third Party Advisory
- https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20VulnerabilitiesVendor Advisory
- https://www.cybersecurity-help.cz/vdb/SB2023033049Third Party Advisory
- https://www.cybersecurity-help.cz/vulnerabilities/74210/Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-26083US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.