Mali GPU 用户空间驱动程序可以进行越界访问 (CVE-2023-32804)

CVE编号

CVE-2023-32804

利用情况

暂无

补丁情况

N/A

披露时间

2023-12-04
漏洞描述
Out-of-bounds Write vulnerability in Arm Ltd Midgard GPU Userspace Driver, Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a local non-privileged user to write a constant pattern to a limited amount of memory not allocated by the user space driver.This issue affects Midgard GPU Userspace Driver: from r0p0 through r32p0; Bifrost GPU Userspace Driver: from r0p0 through r44p0; Valhall GPU Userspace Driver: from r19p0 through r44p0; Arm 5th Gen GPU Architecture Userspace Driver: from r41p0 through r44p0.


解决建议
建议您更新当前系统或软件至最新版,完成漏洞的修复。
受影响软件情况
# 类型 厂商 产品 版本 影响面
1
运行在以下环境
应用 arm 5th_gen_gpu_architecture_kernel_driver * From
(including)
r41p0
Up to
(including)
r44p0
运行在以下环境
应用 arm bifrost_gpu_kernel_driver * From
(including)
r0p0
Up to
(including)
r44p0
运行在以下环境
应用 arm midgard_gpu_kernel_driver * From
(including)
r0p0
Up to
(including)
r32p0
运行在以下环境
应用 arm valhall_gpu_kernel_driver * From
(including)
r19p0
Up to
(including)
r44p0
CVSS3评分
7.8
  • 攻击路径
    本地
  • 攻击复杂度
  • 权限要求
  • 影响范围
    未更改
  • 用户交互
  • 可用性
  • 保密性
  • 完整性
CWE-ID 漏洞类型
CWE-787 跨界内存写
阿里云安全产品覆盖情况