Aller au contenu

Fiche vulnérabilité

CVE-2023-32804 : faille élevée Arm Ltd Midgard GPU Userspace Driver (CVSS 7.8)

Description

Out-of-bounds Write vulnerability in Arm Ltd Midgard GPU Userspace Driver, Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a local non-privileged user to write a constant pattern to a limited amount of memory not allocated by the user space driver.This issue affects Midgard GPU Userspace Driver: from r0p0 through r32p0; Bifrost GPU Userspace Driver: from r0p0 through r44p0; Valhall GPU Userspace Driver: from r19p0 through r44p0; Arm 5th Gen GPU Architecture Userspace Driver: from r41p0 through r44p0.

En bref

Sévérité
Élevée (CVSS 7.8)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
4 déc. 2023
Dernière mise à jour
28 août 2024

Produits concernés

  • Arm Ltd Midgard GPU Userspace Driver
  • Arm Ltd Bifrost GPU Userspace Driver
  • Arm Ltd Valhall GPU Userspace Driver
  • Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver

Correctif et mesures

This issue is fixed in Bifrost, Valhall and Arm 5th Gen GPU Architecture Userspace Driver r44p1 and r45p0. Users are recommended to upgrade if they are impacted by this issue. Please contact Arm support for Midgard GPUs.

Références

Rechercher une autre vulnérabilité dans la base CVE