ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Arm Issues Patch for Mali GPU Kernel Driver Vulnerability Amidst Ongoing Exploitation

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-26083
Memory Leak Information Disclosure in Arm Mali GPU Kernel Drivers

A memory leak (CWE-401) in Arm's Mali GPU kernel drivers affects Midgard (all versions r6p0-r32p0), Bifrost (all versions r0p0-r42p0), Valhall (all versions r19p0-r42p0), and Avalon (r41p0-r42p0), allowing a non-privileged local user to perform valid GPU processing operations that expose sensitive kernel metadata. A local attacker or app on an affected device gains an information-disclosure primitive that reads otherwise protected kernel memory (CVSS 3.1 base score 3.3, confidentiality impact only), potentially aiding further attacks. Exposure applies to any device whose CPU incorporates an affected Mali GPU and runs the corresponding driver, most commonly Android smartphones and tablets built on licensed Mali designs. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2023-04-07), indicating active exploitation, and Arm has issued patched drivers, with fixes also delivered through vendor/Android update channels; ransomware use is unknown.

Do: Apply Arm's patched Mali kernel driver releases (versions beyond the affected ranges) via your SoC/OEM vendor, and on Android devices install the latest Google/OEM security updates, per CISA's required action. Inventory fleets for devices running affected Mali driver generations (Android phones, tablets, and embedded/edge devices) and confirm they receive the fixed driver; note that patching is mandatory for U.S. federal agencies under the KEV program despite the low severity of this local information-disclosure flaw.

3.31% KEV
  • Arm Midgard GPU Kernel Driver all versions r6p0 through r32p0
  • Arm Bifrost GPU Kernel Driver all versions r0p0 through r42p0
  • Arm Valhall GPU Kernel Driver all versions r19p0 through r42p0
  • +2 more
masshundreds of millions of devices (order of magnitude 10^8-10^9) with licensed Mali GPUs and affected driver versions
CVE-2023-33200
A local non-privileged user can make improper GPU processing operations to exploit a software race condition.

A local non-privileged user can make improper GPU processing operations to exploit a software race condition. If the system’s memory is carefully prepared by the user, then this in turn could give them access to already freed memory.

NVD description · AI analysis pending
4.7<1%
  • arm bifrost gpu kernel driver
  • arm mali gpu kernel driver
  • arm valhall gpu kernel driver
CVE-2023-34970
A local non-privileged user can make improper GPU processing operations to access a limited amount outside of buffer bounds or to exploit a software race condit

A local non-privileged user can make improper GPU processing operations to access a limited amount outside of buffer bounds or to exploit a software race condition. If the system’s memory is carefully prepared by the user, then this in turn could give them access to already freed memory

NVD description · AI analysis pending
4.7<1%
  • arm mali gpu kernel driver
  • arm valhall gpu kernel driver
CVE-2023-4211
Use-After-Free in Arm Mali GPU Kernel Driver (Actively Exploited)

CVE-2023-4211 is a use-after-free (CWE-416) in Arm's Mali GPU kernel drivers, covering the Midgard, Bifrost, Valhall and 5th Gen GPU Architecture product lines. A local, non-privileged attacker triggers the flaw by issuing improper GPU memory processing operations, causing the driver to access memory that has already been freed. Successful exploitation exposes already-freed kernel memory to the attacker (high confidentiality impact per the CVSS score), which on mobile devices can be chained into broader local information-gathering or privilege attacks. Any system running the affected Mali kernel drivers is exposed — in practice this is overwhelmingly Android smartphones, tablets and embedded devices whose SoCs integrate Mali GPUs. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2023-10-03, indicating confirmed in-the-wild exploitation; Arm has issued updated drivers, but patch availability varies by device vendor.

Do: Determine whether devices in your fleet use Mali GPUs and obtain updated Mali GPU kernel drivers from Arm via your device vendor's security updates (OEM/Android updates issued from October 2023 onward), since Arm fixes are distributed through device vendors rather than a standalone Arm patch channel. Until devices are patched, limit local, unprivileged access on affected systems to trusted users and monitor vendor bulletins for availability. Per the CISA KEV required action, apply vendor mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

5.51% KEV
  • Arm Mali Midgard GPU kernel driver
  • Arm Mali Bifrost GPU kernel driver
  • Arm Mali Valhall GPU kernel driver
  • +1 more
mass≈1 billion+ devices (Mali GPUs are integrated in a very large share of Android smartphones, tablets and embedded devices)
CVE-2023-4863
Out-of-Bounds Write in Google Chromium WebP Image Codec Actively Exploited

CVE-2023-4863 is a heap-based buffer overflow (CWE-787) in the WebP image codec used by Google Chromium, allowing a remote attacker to write outside the intended bounds of allocated memory. It is triggered when a user visits a crafted HTML page containing malicious WebP image data, so no authentication or special privileges are required, only that the victim loads attacker-controlled content in an affected application. Successful exploitation gives the attacker an out-of-bounds memory write in the affected process, which can lead to application crashes or memory corruption with the potential for code execution. Exposure is unusually broad because, per the advisory, the flaw can affect any application that uses the WebP codec, meaning the browsing public and any software bundling WebP decoding are plausibly in scope. The flaw was added to the CISA KEV catalog on 2023-09-13, indicating confirmed exploitation in the wild; EPSS assigns it a 100% probability of exploitation within 30 days, ransomware use is unknown, and no public proof-of-concept is known.

Do: Update Google Chrome and all other Chromium-based browsers to the latest stable release containing the WebP fix (the patched Chrome 116.0.5845.187 shipped in September 2023), and update or rebuild any other software that bundles the WebP/libwebp codec (fixed in libwebp 1.3.2). Until patching is complete, treat untrusted web content as the attack vector and, per the CISA KEV required action, apply mitigations per vendor instructions or discontinue use of affected software if mitigations are unavailable. Verify remediation by checking installed browser and application versions against the vendor advisories.

8.8100% KEV PoC ×4
  • Google Chromium WebP
mass~3+ billion users (Chromium-based browsers account for roughly two-thirds of global browser usage)
Full article409 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananOct 03, 2023Cyber Attack / Vulnerability

Arm has released security patches to contain a security flaw in the Mali GPU Kernel Driver that has come under active exploitation in the wild.

Tracked as CVE-2023-4211, the shortcoming impacts the following driver versions -

  • Midgard GPU Kernel Driver: All versions from r12p0 - r32p0
  • Bifrost GPU Kernel Driver: All versions from r0p0 - r42p0
  • Valhall GPU Kernel Driver: All versions from r19p0 - r42p0
  • Arm 5th Gen GPU Architecture Kernel Driver: All versions from r41p0 - r42p0

"A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory," Arm said in a Monday advisory. "There is evidence that this vulnerability may be under limited, targeted exploitation."

The issue, credited to Maddie Stone of Google's Threat Analysis Group (TAG) and Jann Horn of Google Project Zero, has been addressed in Bifrost, Valhall and Arm 5th Gen GPU Architecture Kernel Driver r43p0.

Google, in its own monthly Android Security Bulletin for October 2023, said it found indications of targeted exploitation of CVE-2023-4211 and CVE-2023-4863, a severe flaw impacting the WebP image format in the Chrome web browser that was patched last month.

Exact specifics surrounding the nature of the attacks are still unclear, but indications are that they may have been weaponized as part of a spyware campaign targeting high-risk individuals.

Also resolved by Arm are two other flaws in the Mali GPU Kernel Driver that allow for improper GPU memory processing operations -

  • CVE-2023-33200 - A local non-privileged user can make improper GPU processing operations to exploit a software race condition. If the system's memory is carefully prepared by the user, then this in turn could give them access to already freed memory.
  • CVE-2023-34970 - A local non-privileged user can make improper GPU processing operations to access a limited amount outside of buffer bounds or to exploit a software race condition. If the system's memory is carefully prepared by the user, then this, in turn, could give them access to already freed memory.

This is not the first time flaws in Arm Mali GPU Kernel Driver have come under active exploitation. Earlier this year, Google TAG disclosed that CVE-2023-26083 was abused in conjunction with a series of four other flaws by a spyware vendor to penetrate Samsung devices.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/10/arm-issues-patch-for-mali-gpu-kernel.html