VYPR
Unrated severityNVD Advisory· Published Oct 3, 2023· Updated Mar 7, 2025

Mali GPU Kernel Driver Allows Improper GPU Memory Processing Operations

CVE-2023-34970

Description

A local non-privileged user can make improper GPU processing operations to access a limited amount outside of buffer bounds or to exploit a software race condition. If the system’s memory is carefully prepared by the user, then this in turn could give them access to already freed memory

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A local non-privileged user can exploit a buffer overflow or race condition in Arm Mali GPU drivers to access freed memory.

Vulnerability

CVE-2023-34970 is a vulnerability in Arm Mali GPU drivers that allows a local non-privileged user to trigger improper GPU processing operations. This can result in accessing a limited amount of memory outside buffer bounds or exploiting a software race condition. The affected versions include various Mali GPU driver releases; details are available in the Arm security advisory [1].

Exploitation

An attacker with local non-privileged access to the system can carefully prepare the system's memory and then perform specific GPU processing operations. This may involve triggering a race condition or causing an out-of-bounds access. The attacker does not require any special permissions beyond local user access.

Impact

Successful exploitation allows the attacker to access already freed memory. This could lead to information disclosure of sensitive data or potentially be leveraged for privilege escalation, depending on the memory layout and system configuration.

Mitigation

Arm has released updated Mali GPU drivers that fix this vulnerability. Users should apply the latest driver updates from their device vendor. The advisory [1] provides details on the fixed versions and release dates.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.