First published: Mon Feb 05 2024(Updated: )
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improper memory processing operations to exploit a software race condition. If the system’s memory is carefully prepared by the user, then this in turn cause a use-after-free.This issue affects Bifrost GPU Kernel Driver: from r35p0 through r40p0; Valhall GPU Kernel Driver: from r35p0 through r40p0.
Credit: arm-security@arm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Arm Bifrost GPU Kernel Driver | >=r35p0<=r40p0 | |
Arm Ltd Valhall GPU Kernel Driver | >=r35p0<=r40p0 | |
Android |
This issue is fixed in the Bifrost and Valhall Kernel Driver in r41p0. Users are recommended to upgrade if they are impacted by this issue.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-5249 is classified as a high-severity vulnerability due to its potential to allow local non-privileged users to exploit a software race condition.
To mitigate CVE-2023-5249, update the affected Arm Bifrost and Valhall GPU kernel drivers to the latest versions that address this vulnerability.
CVE-2023-5249 affects systems running specific versions of Arm Bifrost and Valhall GPU kernel drivers, as well as devices using the Google Android operating system.
CVE-2023-5249 is a Use After Free vulnerability that can lead to improper memory processing operations.
CVE-2023-5249 requires local access to the affected system for exploitation, meaning it cannot be exploited remotely.