peter bassill · operator
$ cve CVE-2023-26083 JSON

CVE-2023-26083 KEV

3.3
LOW · CVSS 3.1 · EPSS 1.2% (pctl 67)

Patch first

On CISA KEV — known exploited in the wild, due 2023-04-28.

Description

Memory leak vulnerability in Mali GPU Kernel Driver in Midgard GPU Kernel Driver all versions from r6p0 - r32p0, Bifrost GPU Kernel Driver all versions from r0p0 - r42p0, Valhall GPU Kernel Driver all versions from r19p0 - r42p0, and Avalon GPU Kernel Driver all versions from r41p0 - r42p0 allows a non-privileged user to make valid GPU processing operations that expose sensitive kernel metadata.

Scoring

CVSS3.3 (LOW, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS1.22% — more likely to be exploited than 67% of all CVEs
WeaknessCWE-401
On CISA KEVyes — remediate by 2023-04-28
Public exploitnone known
Published2023-04-06
Last modified2026-06-17

CISA KEV

NameArm Mali GPU Kernel Driver Information Disclosure Vulnerability
Added2023-04-07
Due2023-04-28
Vendor / productArm / Mali Graphics Processing Unit (GPU)
Ransomware usenone reported

Affected (4)

VendorProduct
arm5th gen gpu architecture kernel driver
armbifrost gpu kernel driver
armmidgard gpu kernel driver
armvalhall gpu kernel driver

References

→ the Explorer  ·  watch your stack  ·  NVD