Arm Ltd Vulnerabilities and Affected Products
Vulnerabilities associated with Arm 5th Gen GPU Architecture Kernel Driver.
Products
Clear product- Valhall GPU Kernel Driver30 vulnerabilities
- Arm 5th Gen GPU Architecture Kernel Driver21 vulnerabilities
- Bifrost GPU Kernel Driver19 vulnerabilities
- Arm 5th Gen GPU Architecture Kernel Driver6 vulnerabilities
- Midgard GPU Kernel Driver5 vulnerabilities
- Arm 5th Gen GPU Architecture Userspace Driver4 vulnerabilities
- Bifrost GPU Userspace Driver4 vulnerabilities
- Arm Compiler 5 (AC5), Arm Compiler for Embedded 6 (AC6), Fast Models (FM), Arm Compiler for Embedded FuSA (ACEF), Arm Development Studio (ADS), Arm Forge (AF), Arm Mobile Studio (AMS), DS-5 Development Studio, Fast Models (FM), GNU Toolchain (GT), Keil MDK (KMDK), Mbed Studio (MS)3 vulnerabilities
- Valhall GPU Userspace Driver3 vulnerabilities
- Arm 5th Gen GPU Architecture Firmware1 vulnerability
- Arm Compiler for Embedded1 vulnerability
- Arm Compiler for Embedded FuSa 6.16LTS1 vulnerability
- Arm Compiler for Embedded FuSa 6.211 vulnerability
- Arm Compiler for Functional Safety 6.61 vulnerability
- Arm GNU Toolchain1 vulnerability
- CLang1 vulnerability
- Midgard GPU Userspace Driver1 vulnerability
- Valhall GPU Firmware1 vulnerability
- Valhall GPU Userspace Driver1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-5427HIGH | Mali GPU Kernel Driver allows improper GPU processing operationsUse After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU processing operations to gain access to already freed memory.This issue affects Bifrost GPU Kernel Driver: from r44p0 through r45p0; Valhall GPU Kernel Driver: from r44p0 through r45p0; Arm 5th Gen GPU Architecture Kernel Driver: from r44p0 through r45p0. CWE-416Dec 1, 2023 | CVSS7.8v3.1 | EPSS0.334% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-4295HIGH | Mali GPU Kernel Driver allows improper GPU memory processing operationsA local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory. | CVSS7.8v3.1 | EPSS0.251% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-4272MEDIUM | Mali GPU Kernel Driver exposes sensitive data from freed memoryA local non-privileged user can make GPU processing operations that expose sensitive data from previously freed memory. | CVSS5.5v3.1 | EPSS0.34% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-34970MEDIUM | Mali GPU Kernel Driver Allows Improper GPU Memory Processing OperationsA local non-privileged user can make improper GPU processing operations to access a limited amount outside of buffer bounds or to exploit a software race condition. If the system’s memory is carefully prepared by the user, then this in turn could give them access to already freed memory | CVSS4.7v3.1 | EPSS0.292% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-33200MEDIUM | Mali GPU Kernel Driver Allows Improper GPU Memory Processing OperationsA local non-privileged user can make improper GPU processing operations to exploit a software race condition. If the system’s memory is carefully prepared by the user, then this in turn could give them access to already freed memory. CWE-416Oct 3, 2023 | CVSS4.7v3.1 | EPSS0.292% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-4211MEDIUM | Mali GPU Kernel Driver Allows Improper GPU Memory Processing OperationsA local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory. CWE-416Oct 1, 2023 | CVSS5.5v3.1 | EPSS1.36% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |