Memory leak in ARM products - CVE-2023-26083

 

Memory leak in ARM products - CVE-2023-26083

Published: March 30, 2023 / Updated: April 4, 2023


Vulnerability identifier: #VU74210
CSH Severity: High
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-26083
CWE-ID: CWE-401
Exploitation vector: Local access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due memory leak. A local application can force the driver to leak memory and gain access to sensitive information.

Note, this vulnerability is being actively exploited in the wild.


Affected software

Midgard GPU Kernel Driver
ARM Avalon GPU Kernel Driver
Bifrost GPU Kernel Driver
Valhall GPU Kernel Driver
Google Android
Chrome OS

How to mitigate CVE-2023-26083

Install update from vendor's website.

ARM Avalon GPU Kernel Driver - update to r43p0
Bifrost GPU Kernel Driver - update to r43p0
Valhall GPU Kernel Driver - update to r43p0
Google Android - addressed in versions 11 2023-07-05, 12L 2023-07-05, 12 2023-07-05, 13 2023-07-05
Chrome OS - update to 108.0.5359.230

External References

Related Security Bulletins