CVE-2023-4969, also known as "LeftoverLocals," is a medium-severity vulnerability (CVSS 6.5) affecting GPUs from AMD, Imagination Technologies, and Khronos. It allows a malicious GPU kernel to read sensitive data from another GPU kernel, potentially from a different user or application, by exploiting an optimized GPU memory region called local memory. The attack requires local access and has high confidentiality impact, but no integrity or availability impact. While not currently listed in CISA's KEV catalog and lacking public exploit code in Metasploit or ExploitDB, it has garnered significant media attention with two articles and two community mentions, indicating a notable level of awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.0.11CPE matchmatch criteria | cpe:2.3:a:khronos:opencl:*:*:*:*:*:*:*:* | ||
<= 1.3.224CPE matchmatch criteria | cpe:2.3:a:khronos:vulkan:*:*:*:*:*:*:*:* | ||
<= 23.2CPE matchmatch criteria | cpe:2.3:a:imaginationtech:ddk:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:amd:instinct_mi300x_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:amd:instinct_mi300a_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.