CVE-2023-28469
Description
An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to gain access to already freed memory. This affects Valhall r29p0 through r42p0 before r43p0, and Arm's GPU Architecture Gen5 r41p0 through r42p0 before r43p0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A use-after-free vulnerability in Arm Mali GPU Kernel Driver allows a non-privileged user to access freed memory, affecting Valhall r29p0-r42p0 and Gen5 r41p0-r42p0.
Vulnerability
The Arm Mali GPU Kernel Driver contains a use-after-free vulnerability. A non-privileged user can trigger improper GPU processing operations that lead to accessing already freed memory. This affects Valhall GPU Kernel Driver versions r29p0 through r42p0 (fixed in r43p0) and Arm's GPU Architecture Gen5 versions r41p0 through r42p0 (fixed in r43p0). [1]
Exploitation
An attacker requires only non-privileged user access to the system. By performing specific GPU processing operations, the attacker can cause the driver to reference memory that has already been freed, leading to a use-after-free condition. No additional authentication or special privileges are needed beyond local user access. [1]
Impact
Successful exploitation allows the attacker to read or write to freed memory, potentially leading to information disclosure, memory corruption, or escalation of privileges. The exact impact depends on the system configuration and the attacker's ability to control the freed memory contents. [1]
Mitigation
Arm has released version r43p0 for both Valhall and Gen5 architectures, which fixes the vulnerability. Users should update their Mali GPU Kernel Driver to r43p0 or later. No workarounds are mentioned in the available reference. [1]
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Arm/Mali GPU Kernel Driverdescription
- Range: Valhall r29p0 through r42p0 before r43p0; GPU Architecture Gen5 r41p0 through r42p0 before r43p0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.