CVE-2023-4211 is a use-after-free vulnerability affecting Arm's 5th Gen, Bifrost, Midgard, and Valhall GPU kernel drivers. A local non-privileged user can exploit this flaw to gain unauthorized access to previously freed memory, potentially leading to information disclosure. With a CVSS score of 5.5 (Medium), this vulnerability has a low attack complexity and requires local access, but can result in high confidentiality impact. The FAUCET Risk Score of 98/100 indicates significant risk. This CVE is actively exploited in the wild, as confirmed by its presence in the KEV catalog. Despite active exploitation and high community discussion, no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= r41p0, < r43p0CPE matchmatch criteria | cpe:2.3:a:arm:5th_gen_gpu_architecture_kernel_driver:*:*:*:*:*:*:*:* | ||
>= r0p0, < r43p0CPE matchmatch criteria | cpe:2.3:a:arm:bifrost_gpu_kernel_driver:*:*:*:*:*:*:*:* | ||
>= r12p0, <= r32p0CPE matchmatch criteria | cpe:2.3:a:arm:midgard_gpu_kernel_driver:*:*:*:*:*:*:*:* | ||
>= r19p0, < r43p0CPE matchmatch criteria | cpe:2.3:a:arm:valhall_gpu_kernel_driver:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.