7.8
CVSSv3

CVE-2023-48409

Published: 08/12/2023 Updated: 12/03/2024
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

In gpu_pixel_handle_buffer_liveness_update_ioctl of private/google-modules/gpu/mali_kbase/mali_kbase_core_linux.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Vulnerable Product Search on Vulmon Subscribe to Product

google android -

Github Repositories

A kernel exploit for Pixel7/8 Pro with Android 14

Mali GPU Kernel LPE This article provides an in-depth analysis of two kernel vulnerabilities within the Mali GPU, reachable from the default application sandbox, which I independently identified and reported to Google It includes a kernel exploit that achieves arbitrary kernel r/w capabilities Consequently, it disables SELinux and elevates privileges to root on Google Pixel 7