VYPR
Unrated severityNVD Advisory· Published Jun 1, 2023· Updated Jan 9, 2025

CVE-2023-28147

CVE-2023-28147

Description

An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to gain access to already freed memory. This affects Midgard r29p0 through r32p0, Bifrost r17p0 through r42p0 before r43p0, Valhall r19p0 through r42p0 before r43p0, and Arm's GPU Architecture Gen5 r41p0 through r42p0 before r43p0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A use-after-free vulnerability in Arm Mali GPU kernel driver allows non-privileged users to access freed memory, affecting multiple GPU architectures.

Vulnerability

The Arm Mali GPU Kernel Driver contains a use-after-free vulnerability where a non-privileged user can trigger improper GPU processing operations to access already freed memory. This affects Midgard r29p0 through r32p0, Bifrost r17p0 through r42p0 before r43p0, Valhall r19p0 through r42p0 before r43p0, and Arm's GPU Architecture Gen5 r41p0 through r42p0 before r43p0. [1]

Exploitation

An attacker requires only non-privileged user access to the system. By performing specific GPU processing operations, the attacker can cause the driver to reference memory that has already been freed, leading to a use-after-free condition. No additional authentication or special permissions are needed beyond local user access. [1]

Impact

Successful exploitation allows the attacker to read or write freed memory, potentially leading to information disclosure or memory corruption. The attacker may escalate privileges or cause a denial of service. The exact impact depends on the memory layout and system configuration. [1]

Mitigation

Arm has released driver version r43p0 which fixes the vulnerability. Users should update to the latest driver version for their GPU architecture. For affected versions, no workaround is provided; updating is the recommended mitigation. [1]

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Arm/Mali GPU Kernel Driverdescription
  • Range: Midgard r29p0 through r32p0, Bifrost r17p0 through r42p0 before r43p0, Valhall r19p0 through r42p0 before r43p0, Gen5 r41p0 through r42p0 before r43p0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.