CVE-2024-1067Use After Free in ARM 5TH GEN GPU Architecture Kernel Driver

Severity
7.4HIGHNVD
EPSS
0.1%
top 78.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 3

Description

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations. On Armv8.0 cores, there are certain combinations of the Linux Kernel and Mali GPU kernel driver configurations that would allow the GPU operations to affect the userspace memory of other processes. This issue affects Bifrost GPU Kernel Driver: from r41p0 throug

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 1.4 | Impact: 5.9

Affected Packages7 packages

NVDarm/bifrost_gpu_kernel_driverr41p0r48p0
NVDarm/valhall_gpu_kernel_driverr41p0r48p0
CVEListV5arm_ltd/bifrost_gpu_kernel_driverr41p0r47p0
CVEListV5arm_ltd/valhall_gpu_kernel_driverr41p0r47p0

🔴Vulnerability Details

1
GHSA
GHSA-qj33-w9rx-fhcw: Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driv2024-05-03

📋Vendor Advisories

1
Android
CVE-2024-1067: Mali2024-05-01