CVE-2023-4969

MEDIUM

Khronos Opencl < 3.0.11 - Memory Leak

Title source: rule

Description

A GPU kernel can read sensitive data from another GPU kernel (even from another user or app) through an optimized GPU memory region called _local memory_ on various architectures.

Scores

CVSS v3 6.5
EPSS 0.0206
EPSS Percentile 83.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Classification

CWE
CWE-401
Status published

Affected Products (50)

khronos/opencl < 3.0.11
khronos/vulkan < 1.3.224
imaginationtech/ddk < 23.2
amd/instinct_mi300x_firmware
amd/instinct_mi300a_firmware
amd/instinct_mi250_firmware
amd/instinct_mi210_firmware
amd/instinct_mi100_firmware
amd/radeon_instinct_mi50_firmware
amd/radeon_instinct_mi25_firmware
amd/radeon_pro_v620_firmware
amd/radeon_pro_v520_firmware
amd/radeon_pro_w7600_firmware
amd/radeon_pro_w7500_firmware
amd/radeon_pro_w6400_firmware
... and 35 more

Timeline

Published Jan 16, 2024
Tracked Since Feb 18, 2026