CVE-2023-22808: Low severity arm avalon android gralloc module vulnerability
An issue was discovered in the Arm Android Gralloc Module. A non-privileged user can read a small portion of the allocator process memory. This affects Bifrost r24p0 through r41p0 before r42p0, Valhall r24p0 through r41p0 before r42p0, and Avalon r41p0 before r42p0.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-22808?
CVE-2023-22808 is a vulnerability discovered in the Arm Android Gralloc Module, which allows a non-privileged user to read a small portion of the allocator process memory.
Which software is affected by CVE-2023-22808?
The Arm Avalon Android Gralloc Module, Arm Bifrost Android Gralloc Module (r24p0 through r41p0), and Arm Valhall Android Gralloc Module (r24p0 through r41p0) are affected by CVE-2023-22808.
What is the severity of CVE-2023-22808?
CVE-2023-22808 has a severity level of 3.3 (low).
How can I fix CVE-2023-22808?
To fix CVE-2023-22808, it is recommended to update to the latest version of the affected software.
Where can I find more information about CVE-2023-22808?
You can find more information about CVE-2023-22808 on the Arm Security Center website at: https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities