SB2023033049 - Information disclosure in ARM Mali GPU kernel drivers



SB2023033049 - Information disclosure in ARM Mali GPU kernel drivers

Published: March 30, 2023 Updated: April 4, 2023

Security Bulletin ID SB2023033049
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Information disclosure

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Memory leak (CVE-ID: CVE-2023-26083)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due memory leak. A local application can force the driver to leak memory and gain access to sensitive information.

Note, this vulnerability is being actively exploited in the wild.


Remediation

Install update from vendor's website.