CVE-2023-4211
KEVmassUse-After-Free in Arm Mali GPU Kernel Driver (Actively Exploited)
CISA: Arm Mali GPU Kernel Driver Use-After-Free Vulnerability
CVE-2023-4211 is a use-after-free (CWE-416) in Arm's Mali GPU kernel drivers, covering the Midgard, Bifrost, Valhall and 5th Gen GPU Architecture product lines. A local, non-privileged attacker triggers the flaw by issuing improper GPU memory processing operations, causing the driver to access memory that has already been freed. Successful exploitation exposes already-freed kernel memory to the attacker (high confidentiality impact per the CVSS score), which on mobile devices can be chained into broader local information-gathering or privilege attacks. Any system running the affected Mali kernel drivers is exposed — in practice this is overwhelmingly Android smartphones, tablets and embedded devices whose SoCs integrate Mali GPUs. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2023-10-03, indicating confirmed in-the-wild exploitation; Arm has issued updated drivers, but patch availability varies by device vendor.
What to do: Determine whether devices in your fleet use Mali GPUs and obtain updated Mali GPU kernel drivers from Arm via your device vendor's security updates (OEM/Android updates issued from October 2023 onward), since Arm fixes are distributed through device vendors rather than a standalone Arm patch channel. Until devices are patched, limit local, unprivileged access on affected systems to trusted users and monitor vendor bulletins for availability. Per the CISA KEV required action, apply vendor mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
| Arm Mali Midgard GPU kernel driver | — |
| Arm Mali Bifrost GPU kernel driver | — |
| Arm Mali Valhall GPU kernel driver | — |
| Arm Mali 5th Gen GPU Architecture kernel driver | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory.
- Affected
- Arm Mali GPU Kernel Driver
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- arm
- Products
- 5th gen gpu architecture kernel driver, bifrost gpu kernel driver, midgard gpu kernel driver, valhall gpu kernel driver
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N