HIGH · 7.8

CVE-2023-3889

A local non-privileged user can make improper GPU memory processing operations. If the operations are carefully prepared, then they could be used to gain access to already freed memory.

Vulnerability Description

A local non-privileged user can make improper GPU memory processing operations. If the operations are carefully prepared, then they could be used to gain access to already freed memory.

CVSS Score

7.8

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
ArmValhall Gpu Kernel Driver>= r38p0, <= r44p0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-3889?

CVE-2023-3889 is a vulnerability with a CVSS score of 7.8 (HIGH). A local non-privileged user can make improper GPU memory processing operations. If the operations are carefully prepared, then they could be used to gain access to already freed memory.

How severe is CVE-2023-3889?

CVE-2023-3889 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-3889?

Check the references section above for vendor advisories and patch information. Affected products include: Arm Valhall Gpu Kernel Driver.