CVE-2023-4272CWE-1251CWE-200

Mali GPU Kernel Driver exposes sensitive data from freed memory

Medium · published November 7, 2023

CVSS v3.1
5.5
EPSS
0%
Percentile
26.8
In the wild
Unconfirmed
What it is

A local non-privileged user can make GPU processing operations that expose sensitive data from previously freed memory.

The record
Technical detail
CVSS v3.1
5.5 · MEDIUM
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00340 · 26.8th percentile
Weaknesses
CWE-1251 · Mirrored Regions with Different Values; CWE-200 · Exposure of Sensitive Information to an Unauthorized Actor
Published
2023-11-07T15:18Z
EPSS history
Timeline
  • 07 NOV 15:18Z
    Mali GPU Kernel Driver exposes sensitive data from freed memory
    cvelistv5