An issue was discovered in the Arm Android Gralloc Module. A non-privileged user can read a small portion of the allocator process memory. This affects Bifrost r24p0 through r41p0 before r42p0, Valhall r24p0 through r41p0 before r42p0, and Avalon r41p0 before r42p0.
References
Link | Resource |
---|---|
https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities | Vendor Advisory |
https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 07:45
Type | Values Removed | Values Added |
---|---|---|
References | () https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities - Vendor Advisory |
21 Apr 2023, 17:40
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 3.3 |
First Time |
Arm bifrost Android Gralloc Module
Arm avalon Android Gralloc Module Arm valhall Android Gralloc Module Arm |
|
CWE | CWE-125 | |
CPE | cpe:2.3:a:arm:valhall_android_gralloc_module:*:*:*:*:*:*:*:* cpe:2.3:a:arm:bifrost_android_gralloc_module:*:*:*:*:*:*:*:* cpe:2.3:a:arm:avalon_android_gralloc_module:r41p0:*:*:*:*:*:*:* |
|
References | (MISC) https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities - Vendor Advisory |
11 Apr 2023, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-04-11 21:15
Updated : 2025-02-11 21:15
NVD link : CVE-2023-22808
Mitre link : CVE-2023-22808
CVE.ORG link : CVE-2023-22808
JSON object : View
Products Affected
arm
- valhall_android_gralloc_module
- avalon_android_gralloc_module
- bifrost_android_gralloc_module
CWE
CWE-125
Out-of-bounds Read