CVE-2023-4272
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD
Description
A local non-privileged user can make GPU processing operations that expose sensitive data from previously freed memory.
Affected (4)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From r0p0 to r41p0 | |
| Version r41p0 | |
| From r8p0 to r32p0 | |
| From r19p0 to r41p0 |
Related CWEs
CWE-1251
Mirrored Regions with Different Values
The product's architecture mirrors regions without ensuring that their contents always stay in sync.
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
References (2)
Source: arm-security@arm.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.