CVE-2023-3889: Mali GPU Kernel Driver exposes sensitive data from freed memory
Published Nov 7, 2023
·Updated
A local non-privileged user can make improper GPU memory processing operations. If the operations are carefully prepared, then they could be used to gain access to already freed memory.
Affected Software
2 affected components
Google Android
Arm Valhall GPU Kernel Driver>=r38p0<=r44p0
Event History
Nov 7, 2023
CVE Published
via MITRE·03:28 PM
Data Sourced
via MITRE·03:28 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-3889.
2
What is the title of this vulnerability?
The title of this vulnerability is 'Mali GPU Kernel Driver exposes sensitive data from freed memory'.
3
What is the severity of CVE-2023-3889?
The severity of CVE-2023-3889 is high with a CVSS score of 7.8.
4
Which software is affected by CVE-2023-3889?
The Arm Valhall Gpu Kernel Driver with versions r38p0 to r44p0 is affected by CVE-2023-3889.
5
How can this vulnerability be exploited?
A local non-privileged user can exploit this vulnerability by performing improper GPU memory processing operations to gain access to already freed memory.