Lucene search

K
cvelistArmCVELIST:CVE-2024-1067
HistoryMay 03, 2024 - 1:25 p.m.

CVE-2024-1067 Mali GPU Kernel Driver allows improper GPU memory processing operations

2024-05-0313:25:06
CWE-416
Arm
www.cve.org
3
cve-2024-1067
use after free
improper gpu memory processing
armv8.0 cores
linux kernel
local non-privileged user
userspace memory

6.5 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.1%

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations.Β On Armv8.0 cores, there are certain combinations of the Linux Kernel and Mali GPU kernel driver configurations that would allow the GPU operations to affect the userspace memory of other processes.
This issue affects Bifrost GPU Kernel Driver: from r41p0 through r47p0; Valhall GPU Kernel Driver: from r41p0 through r47p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r47p0.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Bifrost GPU Kernel Driver",
    "vendor": "Arm Ltd",
    "versions": [
      {
        "changes": [
          {
            "at": "r48p0",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "r47p0",
        "status": "affected",
        "version": "r41p0",
        "versionType": "patch"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Valhall GPU Kernel Driver",
    "vendor": "Arm Ltd",
    "versions": [
      {
        "changes": [
          {
            "at": "r48p0",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "r47p0",
        "status": "affected",
        "version": "r41p0",
        "versionType": "patch"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Arm 5th Gen GPU Architecture Kernel Driver",
    "vendor": "Arm Ltd",
    "versions": [
      {
        "changes": [
          {
            "at": "r48p0",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "r47p0",
        "status": "affected",
        "version": "r41p0",
        "versionType": "patch"
      }
    ]
  }
]

6.5 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.1%

Related for CVELIST:CVE-2024-1067