← Vulnerability feed

Vulnerability record · CVE-2023-26083 · published 6 April 2023

CVE-2023-26083: Arm Mali GPU Kernel Driver memory leak exposes kernel metadata

Arm · 5th Gen Gpu Architecture Kernel Driver

The Arm Mali GPU kernel driver has a memory leak (CWE-401) across Midgard r6p0-r32p0, Bifrost r0p0-r42p0, Valhall r19p0-r42p0, and Avalon r41p0-r42p0. A non-privileged user can perform valid GPU operations that leak sensitive kernel metadata. The flaw matters because it gives a low-privileged local process a path to kernel information that can aid further attacks.

3.3 CVSS 3.1 Low CISA KEV since 7 Apr 2023 EPSS 1.2% · top 32.6% CWE-401 · Memory leak
3.3CVSS 3.1 base score
1.2%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
4Affected product versions listed by NVD
7References
17 Jun 2026Last modified by NVD

Description

Memory leak vulnerability in Mali GPU Kernel Driver in Midgard GPU Kernel Driver all versions from r6p0 - r32p0, Bifrost GPU Kernel Driver all versions from r0p0 - r42p0, Valhall GPU Kernel Driver all versions from r19p0 - r42p0, and Avalon GPU Kernel Driver all versions from r41p0 - r42p0 allows a non-privileged user to make valid GPU processing operations that expose sensitive kernel metadata.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityCISA KEV listing confirms known exploitation, but the CVSS score is only 3.3 and the flaw is limited to local information disclosure.

What it is

The Arm Mali GPU kernel driver has a memory leak (CWE-401) across Midgard r6p0-r32p0, Bifrost r0p0-r42p0, Valhall r19p0-r42p0, and Avalon r41p0-r42p0. A non-privileged user can perform valid GPU operations that leak sensitive kernel metadata. The flaw matters because it gives a low-privileged local process a path to kernel information that can aid further attacks.

Impact

An attacker gains disclosure of sensitive kernel metadata, which can be used to defeat kernel address space layout randomization and prepare privilege escalation or sandbox escape. No code execution or data modification is provided by this flaw alone.

Attack surface

Reached locally by a non-privileged user issuing valid GPU processing operations through the Mali kernel driver; no user interaction is required and the CVSS vector is AV:L/PR:L/UI:N.

Exploitation

CVE-2023-26083 is listed in CISA KEV with a 2023-04-28 remediation due date, indicating known exploitation, while EPSS 30-day probability is low at 0.01218 (67th percentile). No ransomware campaign use is documented.

What to do

  • Apply the Arm Mali GPU kernel driver updates referenced in the Arm Security Center advisory for the affected Midgard, Bifrost, Valhall, and Avalon branches.
  • If patching cannot be completed immediately, restrict local access to GPU device nodes to trusted users and processes.
  • Track the CISA KEV due date of 2023-04-28 and confirm remediation across all affected devices, including Android and embedded products using Mali GPUs.
  • Monitor vendor advisories for downstream Android and SoC vendor patches, since the Arm driver fix must be delivered through device firmware updates.

Detection

  • Monitor for unusual local processes opening or issuing ioctls to /dev/mali0 or equivalent Mali GPU device nodes.
  • Alert on repeated GPU driver allocation or mapping failures that could indicate memory leak probing.
  • Correlate kernel metadata disclosure attempts with subsequent privilege escalation or sandbox escape activity on the same host.
  • Audit device fleets for unpatched Mali GPU driver versions against the affected r6p0-r32p0, r0p0-r42p0, r19p0-r42p0, and r41p0-r42p0 ranges.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-26083 to the Known Exploited Vulnerabilities catalog on 7 April 2023 as "Arm Mali GPU Kernel Driver Information Disclosure Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 28 April 2023.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-26083 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2022-38181Arm Mali GPU kernel driver use-after-free via mishandled GPU memory operationsThe Arm Mali GPU kernel driver mishandles GPU memory operations, allowing unprivileged users to access freed memory (CWE-416 use-after-free). It affe…KEVEPSS 14%analysed8.8CVE-2021-29256Arm Mali GPU kernel driver use-after-free allows privilege escalationThe Arm Mali GPU kernel driver contains a use-after-free (CWE-416) that an unprivileged user can trigger to access freed memory. Successful exploitat…KEVEPSS 3.0%analysed8.8CVE-2021-28663Arm Mali GPU kernel driver use-after-free privilege escalationThe Arm Mali GPU kernel driver mishandles GPU memory operations, producing a use-after-free in Bifrost, Valhall and Midgard drivers. A local attacker…KEVEPSS 12%analysed8.8CVE-2021-28664Arm Mali GPU kernel driver out-of-bounds write allows privilege escalationThe Arm Mali GPU kernel driver lets an unprivileged user gain read/write access to read-only pages, causing memory corruption. This can lead to privi…KEVEPSS 5.4%analysed7.8CVE-2024-4610Arm Mali GPU kernel driver use-after-free lets local user access freed memoryThe Arm Bifrost and Valhall GPU kernel drivers contain a use-after-free (CWE-416) reachable by a local non-privileged user performing improper GPU me…KEVEPSS 0.76%analysed7.8CVE-2022-22706Arm Mali GPU Kernel Driver read-only memory write flawThe Arm Mali GPU kernel driver lets a non-privileged user gain write access to read-only memory pages, a memory buffer overflow (CWE-119) affecting M…KEVEPSS 1.1%analysed5.5CVE-2023-4211Arm Mali GPU Kernel Driver use-after-free via improper GPU memory handlingThe Arm Mali GPU kernel driver mishandles GPU memory operations, allowing a use-after-free (CWE-416) in which freed memory can be accessed again. A l…KEVEPSS 1.1%analysed9.8CVE-2022-28349Arm bifrost gpu kernel driver use after free vulnerabilityArm Mali GPU Kernel Driver has a use-after-free: Midgard r28p0 through r29p0 before r30p0, Bifrost r17p0 through r23p0 before r24p0, and Valhall r19p…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2023-26083), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.