LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-26083: Arm Mali GPU Kernel Driver Information Disclosure Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 7, 2023
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 28, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-26083 to its Known Exploited Vulnerabilities catalog on Apr 7, 2023, with a federal patch deadline of Apr 28, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Arm Mali GPU Kernel Driver contains an information disclosure vulnerability that allows a non-privileged user to make valid GPU processing operations that expose sensitive kernel metadata.

CVE-2023-26083 is an information disclosure flaw in the Arm Mali GPU Kernel Driver. A non-privileged user can issue valid GPU processing operations that cause the driver to expose sensitive kernel metadata. Because the GPU driver sits close to the kernel and is present on many mobile, embedded, and some desktop systems that use Arm Mali graphics hardware, successful abuse can give an attacker useful internal details that aid further privilege escalation or system compromise. Defenders should treat this as a local information-leak risk that requires inventory and timely patching.

How it works

The vulnerability is classified under CWE-401. In practice, the Arm Mali GPU Kernel Driver fails to properly handle certain resources or state during legitimate GPU operations. A local, unprivileged process can submit ordinary GPU work that triggers the driver to return or leave behind kernel metadata that should remain inaccessible. The attacker does not need to craft malformed packets or exploit a remote service; the operations themselves are valid from the GPU’s perspective. The result is disclosure of sensitive kernel information rather than direct code execution. Exact trigger conditions and the precise metadata that leaks must be confirmed against the vendor advisory; public detail beyond the CISA summary is limited.

Am I affected? How to find it in your systems

Arm Mali GPUs appear in a wide range of Android devices, certain Linux-based embedded platforms, and some Arm-based servers or single-board computers. The vulnerable component is the kernel driver that mediates access to the Mali GPU.

If you cannot determine the driver version, treat the system as potentially affected until the vendor advisory confirms otherwise.

How to remediate

Apply the vendor-supplied updates for the Arm Mali GPU Kernel Driver exactly as instructed by Arm or by the device manufacturer that ships the driver. CISA’s required action is simply to apply those updates. After patching, reboot if required so the new driver is loaded, then verify the running version matches the fixed release.

As additional hardening for this class of kernel-driver information disclosure:

If you can't patch immediately

Until the official update can be installed, reduce the attack surface with compensating controls:

These steps lower risk but do not eliminate the underlying flaw; schedule the vendor update as soon as possible.

If your data may have been exposed

Information-disclosure vulnerabilities of this type can supply an attacker with kernel details that facilitate later privilege escalation or lateral movement. Known ransomware use of CVE-2023-26083 is not documented, yet any successful local compromise can still lead to broader data exposure. If you suspect the driver was abused, examine systems for unauthorized privilege changes, unexpected processes, and signs of further exploitation. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether any associated credentials have already appeared in public leaks.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedArm · Mali Graphics Processing Unit (GPU)
WeaknessCWE-401
Added to CISA KEVApr 7, 2023
Federal patch deadlineApr 28, 2023
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities