Lucene search

K
cveArmCVE-2023-34970
HistoryOct 03, 2023 - 5:15 p.m.

CVE-2023-34970

2023-10-0317:15:09
CWE-787
CWE-416
Arm
web.nvd.nist.gov
38
20
cve-2023-34970
local user
software
race condition
memory access

CVSS3

4.7

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

4.7

Confidence

High

EPSS

0.001

Percentile

29.3%

A local non-privileged user can make improper GPU processing operations to access a limited amount outside of buffer bounds or to exploit a software race condition. If the system’s memory is carefully prepared by the user, then this in turn could give them access to already freed memory

Affected configurations

Nvd
Node
armmali_gpu_kernel_driverMatchr44p0
OR
armvalhall_gpu_kernel_driverMatchr44p0
VendorProductVersionCPE
armmali_gpu_kernel_driverr44p0cpe:2.3:a:arm:mali_gpu_kernel_driver:r44p0:*:*:*:*:*:*:*
armvalhall_gpu_kernel_driverr44p0cpe:2.3:a:arm:valhall_gpu_kernel_driver:r44p0:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Valhall GPU Kernel Driver",
    "vendor": "Arm Ltd",
    "versions": [
      {
        "changes": [
          {
            "at": "r44p1",
            "status": "unaffected"
          }
        ],
        "lessThan": "r44p1",
        "status": "affected",
        "version": "r44p0",
        "versionType": "patch"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Arm 5th Gen GPU Architecture Kernel  Driver",
    "vendor": "Arm Ltd",
    "versions": [
      {
        "changes": [
          {
            "at": "r44p1",
            "status": "unaffected"
          }
        ],
        "lessThan": "r44p1",
        "status": "affected",
        "version": "r41p0",
        "versionType": "patch"
      }
    ]
  }
]

Social References

More

CVSS3

4.7

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

4.7

Confidence

High

EPSS

0.001

Percentile

29.3%

Related for CVE-2023-34970