6.5
CVSSv3

CVE-2023-4969

Published: 16/01/2024 Updated: 23/01/2024
CVSS v3 Base Score: 6.5 | Impact Score: 4 | Exploitability Score: 2
VMScore: 0

Vulnerability Summary

A GPU kernel can read sensitive data from another GPU kernel (even from another user or app) through an optimized GPU memory region called _local memory_ on various architectures.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

khronos vulkan

khronos opencl

imaginationtech ddk

amd instinct_mi300x_firmware -

amd instinct_mi300a_firmware -

amd instinct_mi250_firmware -

amd instinct_mi210_firmware -

amd instinct_mi100_firmware -

amd radeon_instinct_mi50_firmware -

amd radeon_instinct_mi25_firmware -

amd radeon_pro_v620_firmware -

amd radeon_pro_v520_firmware -

amd radeon_pro_w7600_firmware -

amd radeon_pro_w7500_firmware -

amd radeon_pro_w6400_firmware -

amd radeon_pro_w6500m_firmware -

amd radeon_pro_w6300m_firmware -

amd radeon_pro_w5700x_firmware -

amd radeon_pro_w5500x_firmware -

amd radeon_rx_7900xtx_firmware -

amd radeon_rx_7900xt_firmware -

amd radeon_rx_7800xt_firmware -

amd radeon_rx_7700xt_firmware -

amd radeon_rx_7600xt_firmware -

amd radeon_rx_7600_firmware -

amd radeon_rx_6950xt_firmware -

amd radeon_rx_6900xt_firmware -

amd radeon_rx_6800xt_firmware -

amd radeon_rx_6800_firmware -

amd radeon_rx_5300m_firmware -

amd radeon_rx_5300_firmware -

amd radeon_rx_5300xt_firmware -

amd radeon_rx_5500m_firmware -

amd radeon_rx_5500_firmware -

amd radeon_rx_5500xt_firmware -

amd radeon_rx_5600m_firmware -

amd radeon_rx_5600_firmware -

amd radeon_rx_5600xt_firmware -

amd radeon_rx_5700m_firmware -

amd radeon_rx_5700_firmware -

amd radeon_rx_5700xt_firmware -

amd ryzen_9_7945hx3d_firmware -

amd ryzen_9_7945hx_firmware -

amd ryzen_9_7845hx_firmware -

amd ryzen_7_7745hx_firmware -

amd ryzen_5_7645hx_firmware -

amd ryzen_9_7940h_firmware -

amd ryzen_9_pro_7945hs_firmware -

amd ryzen_7_pro_7840hs_firmware -

amd ryzen_7_7840h_firmware -

amd ryzen_7_pro_7840u_firmware -

amd ryzen_5_pro_7640hs_firmware -

amd ryzen_5_7640h_firmware -

amd ryzen_5_pro_7640u_firmware -

amd ryzen_5_pro_7545u_firmware -

amd ryzen_5_pro_7540u_firmware -

amd ryzen_3_7440u_firmware -

amd ryzen_7_5700g_firmware -

amd ryzen_7_5700ge_firmware -

amd ryzen_5_5600gt_firmware -

amd ryzen_5_5600g_firmware -

amd ryzen_5_5600ge_firmware -

amd ryzen_5_5500gt_firmware -

amd ryzen_3_5300g_firmware -

amd ryzen_3_5300ge_firmware -

amd ryzen_5_pro_3400g_firmware -

amd ryzen_5_3400g_firmware -

amd ryzen_5_pro_3400ge_firmware -

amd ryzen_5_pro_3350g_firmware -

amd ryzen_5_pro_3350ge_firmware -

amd ryzen_3_pro_3200g_firmware -

amd ryzen_3_3200g_firmware -

amd ryzen_3_3200ge_firmware -

amd ryzen_3_pro_3200ge_firmware -

amd ryzen_7_7735hs_firmware -

amd ryzen_7_7736u_firmware -

amd ryzen_7_7735u_firmware -

amd ryzen_5_7535hs_firmware -

amd ryzen_5_7535u_firmware -

amd ryzen_3_7335u_firmware -

amd ryzen_5_7520u_firmware -

amd ryzen_3_7320u_firmware -

amd ryzen_9_6980hx_firmware -

amd ryzen_9_6980hs_firmware -

amd ryzen_9_6900hx_firmware -

amd ryzen_9_6900hs_firmware -

amd ryzen_7_6800h_firmware -

amd ryzen_7_6800hs_firmware -

amd ryzen_7_6800u_firmware -

amd ryzen_5_6600h_firmware -

amd ryzen_5_6600hs_firmware -

amd ryzen_5_6600u_firmware -

amd ryzen_7_5700u_firmware -

amd ryzen_5_5500u_firmware -

amd ryzen_3_5300u_firmware -

amd ryzen_9_4900h_firmware -

amd ryzen_9_4900hs_firmware -

amd ryzen_7_4800h_firmware -

amd ryzen_7_4800hs_firmware -

amd ryzen_7_4980u_firmware -

amd ryzen_7_4800u_firmware -

amd ryzen_7_4700u_firmware -

amd ryzen_5_4600h_firmware -

amd ryzen_5_4600hs_firmware -

amd ryzen_5_4680u_firmware -

amd ryzen_5_4600u_firmware -

amd ryzen_5_4500u_firmware -

amd ryzen_3_4300u_firmware -

amd ryzen_3_3250u_firmware -

amd ryzen_3_3250c_firmware -

amd ryzen_3_3200u_firmware -

amd ryzen_9_7950x3d_firmware -

amd ryzen_9_7950x_firmware -

amd ryzen_9_7900x3d_firmware -

amd ryzen_9_7900x_firmware -

amd ryzen_9_7900_firmware -

amd ryzen_9_pro_7945_firmware -

amd ryzen_7_7800x3d_firmware -

amd ryzen_7_7700x_firmware -

amd ryzen_7_7700_firmware -

amd ryzen_7_pro_7745_firmware -

amd ryzen_5_7600x_firmware -

amd ryzen_5_7600_firmware -

amd ryzen_5_pro_7645_firmware -

amd ryzen_5_7500f_firmware -

amd ryzen_7_4700g_firmware -

amd ryzen_7_4700ge_firmware -

amd ryzen_5_4600g_firmware -

amd ryzen_5_4600ge_firmware -

amd ryzen_3_4300g_firmware -

amd ryzen_3_4300ge_firmware -

amd athlon_3000g_firmware -

Vendor Advisories

Debian Bug report logs - #1061460 firmware-nonfree: CVE-2023-4969 Package: src:firmware-nonfree; Maintainer for src:firmware-nonfree is Debian Kernel Team <debian-kernel@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 24 Jan 2024 21:18:02 UTC Severity: important Tags: security, ups ...
Description<!---->A flaw was found in AMD This issue occurs when different users or processes execute independent GPU kernels A compromised AMD GPU kernel could potentially read local memory values from another kernel, which may include private informationA flaw was found in AMD This issue occurs when different users or processes execute indepe ...
Hello All,The Stable channel is being updated to&nbsp;12006099235&nbsp;(Platform version:&nbsp;15662760)&nbsp;for ChromeOS devices and will be rolled out over the next few daysIf you find new issues, please let us know one of the following ways:File a bug&nbsp;Visit our Chrome OS communitiesGeneral:&nbsp;Chromebook Help CommunityBeta Specific ...
LTS-114&nbsp;is being updated in the LTS channel to&nbsp;11405735347 (Platform Version: 15437870)&nbsp;for most ChromeOS devices&nbsp;Want to know more about Long Term Support? Click&nbsp;hereThis update contains multiple Security fixes, including:1500921&nbsp;&nbsp;High&nbsp;&nbsp;CVE-2023-6706 Use after free in FedCM1502102&nbsp;&nbsp;High ...

Recent Articles

Apple, AMD, Qualcomm GPU security hole lets miscreants snoop on AI training and chats
The Register

Topics Security Off-Prem On-Prem Software Offbeat Special Features Vendor Voice Vendor Voice Resources So much for isolation

A design flaw in GPU drivers made by Apple, Qualcomm, AMD, and likely Imagination can be exploited by miscreants on a shared system to snoop on fellow users. That means creeps can, for instance, observe the large language models and other machine-learning software being accelerated by the processors for other users. That will be a worry for those training or running LLMs on a shared server in the cloud. On a non-shared system, malware that manages to run on the box could abuse the weakness to sp...