ZeroHour

CVE-2023-26083

KEVmass

Memory Leak Information Disclosure in Arm Mali GPU Kernel Drivers

CISA: Arm Mali GPU Kernel Driver Information Disclosure Vulnerability

CVSS 3.1
3.3 low
EPSS
1%p67
Published
()
KEV added
AI analysis

A memory leak (CWE-401) in Arm's Mali GPU kernel drivers affects Midgard (all versions r6p0-r32p0), Bifrost (all versions r0p0-r42p0), Valhall (all versions r19p0-r42p0), and Avalon (r41p0-r42p0), allowing a non-privileged local user to perform valid GPU processing operations that expose sensitive kernel metadata. A local attacker or app on an affected device gains an information-disclosure primitive that reads otherwise protected kernel memory (CVSS 3.1 base score 3.3, confidentiality impact only), potentially aiding further attacks. Exposure applies to any device whose CPU incorporates an affected Mali GPU and runs the corresponding driver, most commonly Android smartphones and tablets built on licensed Mali designs. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2023-04-07), indicating active exploitation, and Arm has issued patched drivers, with fixes also delivered through vendor/Android update channels; ransomware use is unknown.

What to do: Apply Arm's patched Mali kernel driver releases (versions beyond the affected ranges) via your SoC/OEM vendor, and on Android devices install the latest Google/OEM security updates, per CISA's required action. Inventory fleets for devices running affected Mali driver generations (Android phones, tablets, and embedded/edge devices) and confirm they receive the fixed driver; note that patching is mandatory for U.S. federal agencies under the KEV program despite the low severity of this local information-disclosure flaw.

Affected
Arm Midgard GPU Kernel Driverall versions r6p0 through r32p0
Arm Bifrost GPU Kernel Driverall versions r0p0 through r42p0
Arm Valhall GPU Kernel Driverall versions r19p0 through r42p0
Arm Avalon GPU Kernel Driverr41p0 through r42p0
Arm 5th Gen GPU Architecture Kernel Driverlisted at architecture level in CPE; no explicit version range in source data
Estimated exposure
masshundreds of millions of devices (order of magnitude 10^8-10^9) with licensed Mali GPUs and affected driver versions — Arm licenses Mali GPU cores to major mobile SoC vendors, so the affected drivers ship across a large share of the world's multi-billion Android install base, though actual exposure depends on each OEM's driver version and update status.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Memory leak vulnerability in Mali GPU Kernel Driver in Midgard GPU Kernel Driver all versions from r6p0 - r32p0, Bifrost GPU Kernel Driver all versions from r0p0 - r42p0, Valhall GPU Kernel Driver all versions from r19p0 - r42p0, and Avalon GPU Kernel Driver all versions from r41p0 - r42p0 allows a non-privileged user to make valid GPU processing operations that expose sensitive kernel metadata.

CISA Known Exploited Vulnerability
Affected
Arm Mali Graphics Processing Unit (GPU)
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
arm
Products
5th gen gpu architecture kernel driver, bifrost gpu kernel driver, midgard gpu kernel driver, valhall gpu kernel driver
Weakness
CWE-401
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news