CVE-2023-34970

MEDIUM

Mali GPU Kernel Driver - Use-After-Free via Improper GPU Processing Operations

Title source: llm
STIX 2.1

Description

A local non-privileged user can make improper GPU processing operations to access a limited amount outside of buffer bounds or to exploit a software race condition. If the system’s memory is carefully prepared by the user, then this in turn could give them access to already freed memory

Scores

CVSS v3 4.7
EPSS 0.0007
EPSS Percentile 20.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-416 CWE-787
Status published
Products (2)
arm/mali_gpu_kernel_driver r44p0
arm/valhall_gpu_kernel_driver r44p0
Published Oct 03, 2023
Tracked Since Feb 18, 2026