CVE-2023-4969

MEDIUM

OpenCL < 3.0.11 - Unprotected Local Memory Data Exposure

Title source: llm
STIX 2.1

Description

A GPU kernel can read sensitive data from another GPU kernel (even from another user or app) through an optimized GPU memory region called _local memory_ on various architectures.

References (5)

Core 5
Core References
Exploit, Mitigation, Third Party Advisory
https://blog.trailofbits.com
Third Party Advisory, US Government Resource
https://kb.cert.org/vuls/id/446598
Third Party Advisory, US Government Resource
https://www.kb.cert.org/vuls/id/446598

Scores

CVSS v3 6.5
EPSS 0.0206
EPSS Percentile 84.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-401
Status published
Products (50)
amd/athlon_3000g_firmware
amd/instinct_mi100_firmware
amd/instinct_mi210_firmware
amd/instinct_mi250_firmware
amd/instinct_mi300a_firmware
amd/instinct_mi300x_firmware
amd/radeon_instinct_mi25_firmware
amd/radeon_instinct_mi50_firmware
amd/radeon_pro_v520_firmware
amd/radeon_pro_v620_firmware
... and 40 more
Published Jan 16, 2024
Tracked Since Feb 18, 2026