CVE-2023-6143Use After Free in ARM 5TH GEN GPU Architecture Kernel Driver

CWE-416Use After Free5 documents4 sources
Severity
8.4HIGHNVD
OSV3.1
EPSS
0.1%
top 68.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 4

Description

Use After Free vulnerability in Arm Ltd Midgard GPU Kernel Driver, Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to exploit a software race condition to perform improper memory processing operations. If the system’s memory is carefully prepared by the user and the system is under heavy load, then this in turn cause a use-after-free.This issue affects Midgard GPU Kernel Driver: from r13p0

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.5 | Impact: 5.9

Affected Packages10 packages

NVDarm/bifrost_gpu_kernel_driverr1p0r19p0
NVDarm/valhall_gpu_kernel_driverr37p0r47p0
NVDarm/midgard_gpu_kernel_driverr13p0r32p0
CVEListV5arm_ltd/bifrost_gpu_kernel_driverr1p0r18p0

🔴Vulnerability Details

3
GHSA
GHSA-f279-w6jr-7xxj: Use After Free vulnerability in Arm Ltd Midgard GPU Kernel Driver, Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 52024-03-04
OSV
firefox regressions2023-06-21
OSV
firefox regressions2023-06-13

📋Vendor Advisories

1
Android
CVE-2023-6143: Mali2024-03-01