CVE-2023-33200 is a software race condition vulnerability affecting Arm Bifrost, Mali, and Valhall GPU kernel drivers. A local, non-privileged user can trigger improper GPU processing operations, potentially leading to access of freed memory. While rated Medium severity (CVSS 4.7) due to high attack complexity and requiring local access, it could result in high availability impact. Although no public exploit code exists, community discussion and media coverage indicate this vulnerability has been actively exploited in targeted attacks, warranting prompt patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= r17p0, < r44p1CPE matchmatch criteria | cpe:2.3:a:arm:bifrost_gpu_kernel_driver:*:*:*:*:*:*:*:* | ||
>= r41p0, < r44p1CPE matchmatch criteria | cpe:2.3:a:arm:mali_gpu_kernel_driver:*:*:*:*:*:*:*:* | ||
>= r19p0, < r44p1CPE matchmatch criteria | cpe:2.3:a:arm:valhall_gpu_kernel_driver:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.