« Volver al listado

CVE-2023-4272

Estado: ModificadaMedia (5.5)—

A local non-privileged user can make GPU processing operations that expose sensitive data from previously freed memory.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-4272",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-4272",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-09-04T19:32:51.694412Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "arm-security@arm.com",
      "affectedData": [
        {
          "vendor": "Arm Ltd",
          "product": "Midgard GPU Kernel Driver",
          "versions": [
            {
              "status": "affected",
              "version": "r8p0",
              "versionType": "patch",
              "lessThanOrEqual": "r32p0"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Arm Ltd",
          "product": "Bifrost GPU Kernel Driver",
          "versions": [
            {
              "status": "affected",
              "changes": [
                {
                  "at": "r42p0",
                  "status": "unaffected"
                }
              ],
              "version": "r0p0",
              "lessThan": "r42p0",
              "versionType": "patch"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Arm Ltd",
          "product": "Valhall GPU Kernel Driver",
          "versions": [
            {
              "status": "affected",
              "changes": [
                {
                  "at": "r42p0",
                  "status": "unaffected"
                }
              ],
              "version": "r19p0",
              "lessThan": "r42p0",
              "versionType": "patch"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Arm Ltd",
          "product": "Arm 5th Gen GPU Architecture Kernel  Driver",
          "versions": [
            {
              "status": "affected",
              "changes": [
                {
                  "at": "r42p0",
                  "status": "unaffected"
                }
              ],
              "version": "r41p0",
              "lessThan": "r42p0",
              "versionType": "patch"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-11-07T16:15:29.250",
  "references": [
    {
      "url": "https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "arm-security@arm.com"
    },
    {
      "url": "https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "arm-security@arm.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        },
        {
          "lang": "en",
          "value": "CWE-1251"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A local non-privileged user can make GPU processing operations that expose sensitive data from previously freed memory. \n\n"
    },
    {
      "lang": "es",
      "value": "Un usuario local sin privilegios puede realizar operaciones de procesamiento de GPU que expongan datos confidenciales de la memoria previamente liberada."
    }
  ],
  "lastModified": "2026-06-17T06:37:27.060",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:arm:bifrost_gpu_kernel_driver:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "711E2235-8C0F-4B8F-858F-E2EAAC124FA1",
              "versionEndIncluding": "r41p0",
              "versionStartIncluding": "r0p0"
            },
            {
              "criteria": "cpe:2.3:a:arm:mali_gpu_kernel_driver:r41p0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4B4EFDF6-BB81-48DF-BCC9-C22657E572AC"
            },
            {
              "criteria": "cpe:2.3:a:arm:midgard_gpu_kernel_driver:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1B466A44-0367-4F71-ABF0-CB031338B7E6",
              "versionEndIncluding": "r32p0",
              "versionStartIncluding": "r8p0"
            },
            {
              "criteria": "cpe:2.3:a:arm:valhall_gpu_kernel_driver:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2429D309-6700-447D-A068-F6F02DC6473B",
              "versionEndIncluding": "r41p0",
              "versionStartIncluding": "r19p0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "arm-security@arm.com"
}