Out-of-bounds read in ARM Avalon GPU Kernel Driver and Valhall GPU Kernel Driver - CVE-2022-46396

 

Out-of-bounds read in ARM Avalon GPU Kernel Driver and Valhall GPU Kernel Driver - CVE-2022-46396

Published: April 4, 2023


Vulnerability identifier: #VU74393
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-46396
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local application to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition. A local application can trigger an out-of-bounds read error and read contents of memory on the system.


Affected software

ARM Avalon GPU Kernel Driver
Valhall GPU Kernel Driver
Samsung Mobile Firmware
Google Android

How to mitigate CVE-2022-46396

Install updates from vendor's website.

ARM Avalon GPU Kernel Driver - update to r42p0
Valhall GPU Kernel Driver - update to r42p0
Samsung Mobile Firmware - update to SMR-JUN-2023
Google Android - addressed in versions 11 2023-05-05, 12L 2023-05-05, 12 2023-05-05, 13 2023-05-05

External References

Related Security Bulletins