First published: Tue Nov 07 2023(Updated: )
A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory.
Credit: arm-security@arm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Arm Mali GPU Kernel Driver | >=r41p0<r43p0 | |
Arm Valhall Gpu Kernel Driver | >=r29p0<=r42p0 | |
Google Android |
This issue is fixed in Valhall and Arm 5th Gen GPU Architecture Kernel Driver r43p0. Users are recommended to upgrade if they are impacted by this issue.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-4295 is a vulnerability in the Mali GPU Kernel Driver that allows improper GPU memory processing operations.
The vulnerability affects local non-privileged users.
An attacker can gain access to already freed memory.
The severity of CVE-2023-4295 is high with a CVSS score of 7.8.
To fix CVE-2023-4295, it is recommended to apply the necessary security patches provided by Arm.