VYPR
Unrated severityNVD Advisory· Published Jun 2, 2023· Updated Jan 8, 2025

CVE-2023-28469

CVE-2023-28469

Description

An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to gain access to already freed memory. This affects Valhall r29p0 through r42p0 before r43p0, and Arm's GPU Architecture Gen5 r41p0 through r42p0 before r43p0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A use-after-free vulnerability in Arm Mali GPU Kernel Driver allows a non-privileged user to access freed memory, affecting Valhall r29p0-r42p0 and Gen5 r41p0-r42p0.

Vulnerability

The Arm Mali GPU Kernel Driver contains a use-after-free vulnerability. A non-privileged user can trigger improper GPU processing operations that lead to accessing already freed memory. This affects Valhall GPU Kernel Driver versions r29p0 through r42p0 (fixed in r43p0) and Arm's GPU Architecture Gen5 versions r41p0 through r42p0 (fixed in r43p0). [1]

Exploitation

An attacker requires only non-privileged user access to the system. By performing specific GPU processing operations, the attacker can cause the driver to reference memory that has already been freed, leading to a use-after-free condition. No additional authentication or special privileges are needed beyond local user access. [1]

Impact

Successful exploitation allows the attacker to read or write to freed memory, potentially leading to information disclosure, memory corruption, or escalation of privileges. The exact impact depends on the system configuration and the attacker's ability to control the freed memory contents. [1]

Mitigation

Arm has released version r43p0 for both Valhall and Gen5 architectures, which fixes the vulnerability. Users should update their Mali GPU Kernel Driver to r43p0 or later. No workarounds are mentioned in the available reference. [1]

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Arm/Mali GPU Kernel Driverdescription
  • Range: Valhall r29p0 through r42p0 before r43p0; GPU Architecture Gen5 r41p0 through r42p0 before r43p0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.