CVE-2023-4969
MEDIUMOpenCL < 3.0.11 - Unprotected Local Memory Data Exposure
Title source: llmDescription
A GPU kernel can read sensitive data from another GPU kernel (even from another user or app) through an optimized GPU memory region called _local memory_ on various architectures.
References (5)
Core 5
Core References
Exploit, Mitigation, Third Party Advisory
https://blog.trailofbits.com
Third Party Advisory, US Government Resource
https://kb.cert.org/vuls/id/446598
Technical Description
https://registry.khronos.org/OpenCL/specs/3.0-unified/html/OpenCL_API.html#_fundamental_memory_regions
Third Party Advisory, US Government Resource
https://www.kb.cert.org/vuls/id/446598
Scores
CVSS v3
6.5
EPSS
0.0206
EPSS Percentile
84.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-401
Status
published
Products (50)
amd/athlon_3000g_firmware
amd/instinct_mi100_firmware
amd/instinct_mi210_firmware
amd/instinct_mi250_firmware
amd/instinct_mi300a_firmware
amd/instinct_mi300x_firmware
amd/radeon_instinct_mi25_firmware
amd/radeon_instinct_mi50_firmware
amd/radeon_pro_v520_firmware
amd/radeon_pro_v620_firmware
... and 40 more
Published
Jan 16, 2024
Tracked Since
Feb 18, 2026