First published: Fri Dec 01 2023(Updated: )
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU processing operations to gain access to already freed memory.This issue affects Bifrost GPU Kernel Driver: from r44p0 through r45p0; Valhall GPU Kernel Driver: from r44p0 through r45p0; Arm 5th Gen GPU Architecture Kernel Driver: from r44p0 through r45p0.
Credit: arm-security@arm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Arm 5th Gen GPU Architecture Kernel Driver | >=r44p0<r46p0 | |
Arm Bifrost Gpu Kernel Driver | >=r44p0<r46p0 | |
Arm Valhall Gpu Kernel Driver | >=r44p0<r46p0 | |
Google Android |
This issue is fixed in Bifrost, Valhall, and Arm 5th Gen GPU Architecture Kernel Driver r46p0. Users are recommended to upgrade if they are impacted by this issue.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2023-5427 is a vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver that allows a local non-privileged user to make improper GPU processing operations to gain access to already freed memory.
CVE-2023-5427 has a severity rating of 7.8 (high).
Arm 5th Gen GPU Architecture Kernel Driver, Arm Bifrost GPU Kernel Driver, and Arm Valhall GPU Kernel Driver versions ranging from r44p0 to r46p0 are affected by CVE-2023-5427.
A local non-privileged user can exploit CVE-2023-5427 by making improper GPU processing operations to gain access to already freed memory.
You can find more information about CVE-2023-5427 at the Arm Security Center's website and Packet Storm Security's website.