NA

CVE-2023-26083

Published: 06/04/2023 Updated: 21/04/2023
CVSS v3 Base Score: 3.3 | Impact Score: 1.4 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

Memory leak vulnerability in Mali GPU Kernel Driver in Midgard GPU Kernel Driver all versions from r6p0 - r32p0, Bifrost GPU Kernel Driver all versions from r0p0 - r42p0, Valhall GPU Kernel Driver all versions from r19p0 - r42p0, and Avalon GPU Kernel Driver all versions from r41p0 - r42p0 allows a non-privileged user to make valid GPU processing operations that expose sensitive kernel metadata.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

arm midgard

arm bifrost gpu kernel driver

arm valhall gpu kernel driver

arm avalon gpu kernel driver

Vendor Advisories

LTS-108 is being updated in the LTS channel to 10805359230 (Platform Version: 15183930) for most ChromeOS devices Want to know more about Long Term Support? Click hereThis update contains multiple Security fixes, including:1421268 High  CVE-2023-1532 Out of bounds read in GPU Video1420510 High&nbs ...

Github Repositories

A kernel exploit for Pixel7/8 Pro with Android 14

Mali GPU Kernel LPE This article provides an in-depth analysis of two kernel vulnerabilities within the Mali GPU, reachable from the default application sandbox, which I independently identified and reported to Google It includes a kernel exploit that achieves arbitrary kernel r/w capabilities Consequently, it disables SELinux and elevates privileges to root on Google Pixel 7