ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

NVIDIA and Arm Urge Customers to Patch Bugs

criticalVulnerability exploited in the wildimportance 60CVE-2024-4610

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-4610
Use-After-Free in Arm Mali Bifrost/Valhall GPU Kernel Drivers Exploited in the Wild

CVE-2024-4610 is a use-after-free (CWE-416) in Arm's Bifrost and Valhall Mali GPU kernel drivers, affecting driver builds from r34p0 through r40p0. A local, non-privileged user can trigger improper GPU memory processing operations that cause the driver to access already-freed memory. A successful exploit can yield high-impact outcomes — confidentiality, integrity and availability are all rated high, implying kernel-level information disclosure or code execution in the context of the GPU driver — and it could also be chained with other bugs in remote exploitation chains. Any device shipping a Mali Bifrost/Valhall driver in the affected range is exposed, including Android smartphones and other SoC-based products from vendors that integrate Mali GPUs. The flaw is being actively exploited in the wild: Arm warned of in-the-wild zero-day use, CISA added it to the Known Exploited Vulnerabilities catalog on 2024-06-12, and related reporting ties it to spyware-grade exploitation (Intellexa/Predator and a Google warning about a Pixel firmware zero-day).

Do: Update to a fixed Arm Mali Bifrost/Valhall GPU kernel driver release newer than r40p0, which for most users means applying the latest Android/SoC/device vendor firmware updates (e.g., Google's updated Pixel firmware). Organizations managing fleets should inventory devices built on affected Mali driver versions (Pixel, MediaTek Dimensity, Exynos handsets; Rockchip/Amlogic boards) and prioritize them for patching given confirmed in-the-wild exploitation. Federal agencies must apply vendor mitigations per CISA KEV requirements within the mandated deadline, and defenders should treat local or chained remote exploitation paths as realistic, consistent with the spyware-usage reporting.

7.8<1% KEV
  • Arm Bifrost GPU Kernel Driver r34p0 through r40p0
  • Arm Valhall GPU Kernel Driver r34p0 through r40p0
mass≈hundreds of millions of Android devices and SoC-based systems with Mali Bifrost/Valhall GPUs in the affected driver range
Full article299 words · extracted from infosecurity-magazine.com · click to collapse

NVIDIA and Arm have urged customers to upgrade their products after revealing a series of new vulnerabilities.

Arm announced an actively exploited zero-day vulnerability in its Mali GPU Kernel Driver which allows “improper GPU memory processing operations.”

Listed as CVE-2024-4610, the vulnerability impacts all versions of its Bifrost and Valhall drivers, from r34p0 to r40p0.

“A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory,” the advisory noted. “Arm is aware of reports of this vulnerability being exploited in the wild. Users are recommended to upgrade if they are impacted by this issue.”

Read more on chip-level vulnerabilities: Critical Vulnerability Found in Motorola’s Unisoc Chips

Meanwhile, a new NVIDIA security bulletin for June revealed 10 new high and medium-severity vulnerabilities in its GPU Display Driver and VGPU software products.

Security experts highlighted CVE‑2024‑0090 as potentially the most serious. The out-of-bounds write bug could lead to code execution, denial of service, escalation of privileges, information disclosure and data tampering, NVIDIA said.

“CVE‑2024‑0090 is concerning given its versatility to an attacker, the fact that it affects both Windows and Linux, and the ubiquity of Nvidia GPUs in the overall attack surface,” argued Bugcrowd founder, Casey Ellis. “I wouldn’t be surprised to see it included in attack tooling in the not-too-distant future.”

John Bambenek, president of Bambenek Consulting, also urged caution.

“Judging from the CVSS scores, it doesn’t seem that NVIDIA believes remote execution of these vulnerabilities is possible,” he argued.

“The concern here is that sometimes device drivers can be overlooked as part of the patching process, especially when not part of the OS patch process. Therefore, special effort may be needed to find these vulnerable systems and patch them, which will likely require a reboot.”

Image credit: Ascannio / Shutterstock.com

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/nvidia-arm-urge-customers-patch/