Vulnerabilities
Vulnerable Software
Arm:  Security Vulnerabilities
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU processing operations to gain access to already freed memory.This issue affects Bifrost GPU Kernel Driver: from r44p0 through r45p0; Valhall GPU Kernel Driver: from r44p0 through r45p0; Arm 5th Gen GPU Architecture Kernel Driver: from r44p0 through r45p0.
CVSS Score
7.8
EPSS Score
0.001
Published
2023-12-01
A local non-privileged user can make GPU processing operations that expose sensitive data from previously freed memory.
CVSS Score
5.5
EPSS Score
0.003
Published
2023-11-07
A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory.
CVSS Score
7.8
EPSS Score
0.001
Published
2023-11-07
A local non-privileged user can make improper GPU memory processing operations. If the operations are carefully prepared, then they could be used to gain access to already freed memory.
CVSS Score
7.8
EPSS Score
0.001
Published
2023-11-07
Mbed TLS 2.x before 2.28.5 and 3.x before 3.5.0 has a Buffer Overflow.
CVSS Score
7.5
EPSS Score
0.003
Published
2023-10-07
Mbed TLS 3.2.x through 3.4.x before 3.5 has a Buffer Overflow that can lead to remote Code execution.
CVSS Score
9.8
EPSS Score
0.093
Published
2023-10-07
A local non-privileged user can make improper GPU processing operations to exploit a software race condition. If the system’s memory is carefully prepared by the user, then this in turn could give them access to already freed memory.
CVSS Score
4.7
EPSS Score
0.001
Published
2023-10-03
A local non-privileged user can make improper GPU processing operations to access a limited amount outside of buffer bounds or to exploit a software race condition. If the system’s memory is carefully prepared by the user, then this in turn could give them access to already freed memory
CVSS Score
4.7
EPSS Score
0.001
Published
2023-10-03
CVE-2023-4211
Known exploited
A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory.
CVSS Score
5.5
EPSS Score
0.003
Published
2023-10-01
In Trusted Firmware-M through TF-Mv1.8.0, for platforms that integrate the CryptoCell accelerator, when the CryptoCell PSA Driver software Interface is selected, and the Authenticated Encryption with Associated Data Chacha20-Poly1305 algorithm is used, with the single-part verification function (defined during the build-time configuration phase) implemented with a dedicated function (i.e., not relying on usage of multipart functions), the buffer comparison during the verification of the authentication tag does not happen on the full 16 bytes but just on the first 4 bytes, thus leading to the possibility that unauthenticated payloads might be identified as authentic. This affects TF-Mv1.6.0, TF-Mv1.6.1, TF-Mv1.7.0, and TF-Mv1.8.
CVSS Score
7.5
EPSS Score
0.002
Published
2023-09-08


Contact Us

Shodan ® - All rights reserved