LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-4211: Arm Mali GPU Kernel Driver Use-After-Free Vulnerability

RBRecent Breaches Vulnerability Intelligence·Oct 3, 2023
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Oct 24, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-4211 to its Known Exploited Vulnerabilities catalog on Oct 3, 2023, with a federal patch deadline of Oct 24, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that allows a local, non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.

CVE-2023-4211 is a use-after-free vulnerability in the Arm Mali GPU Kernel Driver. It lets a local, non-privileged user perform improper GPU memory processing operations and gain access to memory that has already been freed. Because the driver runs in the kernel, successful abuse can lead to elevated privileges or further compromise of the host. Defenders should treat it as a high-priority local privilege-escalation risk on any system that uses the affected driver and confirm exact impact and fixed versions against the vendor advisory.

The issue matters for mobile devices, embedded systems, and any platform that incorporates Arm Mali GPUs. Local attackers who already have a foothold can leverage it to expand control, so inventory and rapid remediation are essential.

How it works

The vulnerability belongs to CWE-416 (use-after-free). In the Arm Mali GPU Kernel Driver, memory that has been freed can still be referenced during certain GPU memory-processing operations. A local, non-privileged process can trigger those operations in a way that causes the driver to operate on the freed memory. This class of flaw typically allows an attacker to corrupt kernel structures or read/write sensitive data, potentially resulting in privilege escalation or arbitrary code execution in kernel context. Exact trigger conditions and memory-layout details are not provided in public summaries and must be confirmed against the vendor advisory; no exploit code or specific mechanics beyond the CISA description should be assumed.

Am I affected? How to find it in your systems

Arm Mali GPU Kernel Drivers are commonly found on Android devices, certain Linux-based embedded platforms, and other systems that use Mali graphics hardware. Inventory steps include:

Because public detail on exact version ranges is limited, always cross-check the vendor advisory rather than relying on generic version lists.

How to remediate

Apply the vendor-supplied update that addresses CVE-2023-4211 as the primary remediation. Follow the instructions published by Arm or by the device OEM that ships the Mali driver. CISA guidance is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. After patching:

If you can't patch immediately

Until the vendor update can be deployed, reduce exposure with compensating controls:

These measures do not eliminate the vulnerability but raise the cost of exploitation until a permanent fix is in place.

If your data may have been exposed

Actively exploited local privilege-escalation vulnerabilities can lead to broader system compromise and data exposure. Known ransomware use of this CVE is not documented. If you suspect an attacker may have used the flaw, examine host logs for signs of unauthorized privilege elevation and consider rotating credentials and secrets that were accessible from the affected system. You can also run a free exposure scan of your email addresses to check whether those addresses appear in known breach data sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedArm · Mali GPU Kernel Driver
WeaknessCWE-416
Added to CISA KEVOct 3, 2023
Federal patch deadlineOct 24, 2023
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities