Database/Kernel, userspace & hypervisor
Arm Mali GPU kernel driver: Use-after-free via improper GPU memory processing
CVSS 5.5CVE-2023-4211Kernel, userspace & hypervisorKnown exploitedcurated
Impact
Use-after-free via improper GPU memory processing - local non-privileged user reaches freed memory; exploited in the wild [KEV]
Who can reach it
Local user with GPU device access
What to do
Driver update + reboot
References
Related entries
- Arm Mali GPU kernel driver: Use-after-free in the Bifrost/Valhall GPU kernel driverCVE-2024-4610 · Arm Mali GPU kernel driverHigh
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A race condition or locking defect in the amdkfd (KFDCVE-2023-52632 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)Medium
- Linux kernel BPF verifier: stack bound arithmetic done in 32 bits could overflowCVE-2023-52676 · Linux kernel BPF verifier (stack bounds arithmetic in kernel/bpf/verifier.c)Medium
- Linux kernel (net/tls): Sendfile() on a kTLS socket whose plaintext and ciphertext buffers are both empty drives theCVE-2023-52767 · Linux kernel (net/tls)Medium
- Linux cpufreq/amd-pstate-ut - kernel panic when loading the unit-test driver: Loading the amd-pstate unit-test moduleCVE-2023-53563 · Linux cpufreq/amd-pstate-ut - kernel panic when loading the unit-test driverMedium
- Linux kernel (net/xfrm): Structure padding in the xfrm algorithm and encapsulation templates was copied to userspaceCVE-2023-53684 · Linux kernel (net/xfrm)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.