Semiconductor giants Nvidia and Arm warn of new flaws in their graphics processors
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-4211 | Use-After-Free in Arm Mali GPU Kernel Driver (Actively Exploited) CVE-2023-4211 is a use-after-free (CWE-416) in Arm's Mali GPU kernel drivers, covering the Midgard, Bifrost, Valhall and 5th Gen GPU Architecture product lines. A local, non-privileged attacker triggers the flaw by issuing improper GPU memory processing operations, causing the driver to access memory that has already been freed. Successful exploitation exposes already-freed kernel memory to the attacker (high confidentiality impact per the CVSS score), which on mobile devices can be chained into broader local information-gathering or privilege attacks. Any system running the affected Mali kernel drivers is exposed — in practice this is overwhelmingly Android smartphones, tablets and embedded devices whose SoCs integrate Mali GPUs. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2023-10-03, indicating confirmed in-the-wild exploitation; Arm has issued updated drivers, but patch availability varies by device vendor. Do: Determine whether devices in your fleet use Mali GPUs and obtain updated Mali GPU kernel drivers from Arm via your device vendor's security updates (OEM/Android updates issued from October 2023 onward), since Arm fixes are distributed through device vendors rather than a standalone Arm patch channel. Until devices are patched, limit local, unprivileged access on affected systems to trusted users and monitor vendor bulletins for availability. Per the CISA KEV required action, apply vendor mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | 5.5 | 1% | KEV |
| mass≈1 billion+ devices (Mali GPUs are integrated in a very large share of Android smartphones, tablets and embedded devices) | |
| CVE-2024-4610 | Use-After-Free in Arm Mali Bifrost/Valhall GPU Kernel Drivers Exploited in the Wild CVE-2024-4610 is a use-after-free (CWE-416) in Arm's Bifrost and Valhall Mali GPU kernel drivers, affecting driver builds from r34p0 through r40p0. A local, non-privileged user can trigger improper GPU memory processing operations that cause the driver to access already-freed memory. A successful exploit can yield high-impact outcomes — confidentiality, integrity and availability are all rated high, implying kernel-level information disclosure or code execution in the context of the GPU driver — and it could also be chained with other bugs in remote exploitation chains. Any device shipping a Mali Bifrost/Valhall driver in the affected range is exposed, including Android smartphones and other SoC-based products from vendors that integrate Mali GPUs. The flaw is being actively exploited in the wild: Arm warned of in-the-wild zero-day use, CISA added it to the Known Exploited Vulnerabilities catalog on 2024-06-12, and related reporting ties it to spyware-grade exploitation (Intellexa/Predator and a Google warning about a Pixel firmware zero-day). Do: Update to a fixed Arm Mali Bifrost/Valhall GPU kernel driver release newer than r40p0, which for most users means applying the latest Android/SoC/device vendor firmware updates (e.g., Google's updated Pixel firmware). Organizations managing fleets should inventory devices built on affected Mali driver versions (Pixel, MediaTek Dimensity, Exynos handsets; Rockchip/Amlogic boards) and prioritize them for patching given confirmed in-the-wild exploitation. Federal agencies must apply vendor mitigations per CISA KEV requirements within the mandated deadline, and defenders should treat local or chained remote exploitation paths as realistic, consistent with the spyware-usage reporting. | 7.8 | <1% | KEV |
| mass≈hundreds of millions of Android devices and SoC-based systems with Mali Bifrost/Valhall GPUs in the affected driver range |
Full article437 words · extracted from therecord.media · click to collapse
The major semiconductor companies Arm and Nvidia are urging customers to apply patches for a series of new vulnerabilities in their products. The U.K.-based Arm warned on Friday about an actively exploited zero-day flaw in its Mali GPU Kernel Driver — software that helps the operating system communicate with the Mali graphics processor. The vulnerability, tracked as CVE-2024-4610, can lead to “improper GPU memory processing operations,” potentially causing security issues such as crashes, data corruption, or unauthorized access to sensitive information. Arm said that it is aware of reports of this vulnerability being exploited in the wild and has already fixed the bug. The company recommends its users upgrade their Bifrost and Valhall GPU kernel drivers if they are impacted by this issue. This isn't the first time researchers have discovered issues in Arm's Mali GPU kernel driver. In October, the company said that a security issue, tracked as CVE-2023-4211, could allow hackers to gain access to data stored on devices that use Mali GPU. Last year, a researcher known as Man Yue Mo on GitHub identified a security vulnerability in the Mali GPU kernel driver that could have enabled hackers to gain control over the operating system of the Google Pixel 6. That issue was fixed in June 2022. The U.S.-based GPU designer and manufacturer, Nvidia, also revealed on Thursday 10 new high and medium-severity vulnerabilities in its GPU Display Driver and vGPU software products. The flaw tracked as CVE‑2024‑0090, which was discovered in Nvidia’s GPU driver for Windows and Linux, might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering, the company said. Nvidia’s GPU Display Driver for Windows also contains a vulnerability — CVE‑2024‑0089 — “where information from a previous client or another process could be disclosed.” Another flaw tracked as CVE‑2024‑0099, which was discovered in Nvidia's virtual GPU (vGPU) — software that allows multiple virtual machines to share a single physical GPU — could also lead to information disclosure, data tampering, escalation of privileges, and denial of service. Nvidia didn’t mention if either of these flaws was exploited in the wild. The company advised its users to download and install the software updates to protect their systems from potential abuse by hackers.
No previous article
No new articles
Daryna Antoniuk
is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/nvidia-arm-semiconductor-flaws-patches