← Vulnerability feed

Vulnerability record · CVE-2023-4211 · published 1 October 2023

CVE-2023-4211: Arm Mali GPU Kernel Driver use-after-free via improper GPU memory handling

Arm · 5th Gen Gpu Architecture Kernel Driver

The Arm Mali GPU kernel driver mishandles GPU memory operations, allowing a use-after-free (CWE-416) in which freed memory can be accessed again. A local non-privileged user can trigger it, and the flaw affects the Midgard, Bifrost, Valhall and 5th Gen GPU architecture kernel drivers. It matters because freed kernel memory exposure can leak sensitive data and is a common building block for privilege escalation in GPU drivers.

5.5 CVSS 3.1 Medium CISA KEV since 3 Oct 2023 EPSS 1.1% · top 35.7% CWE-416 · Use after free
5.5CVSS 3.1 base score
1.1%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
4Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityIt is listed in CISA KEV with confirmed in-the-wild exploitation, though the CVSS score is only 5.5 and the impact is limited to confidentiality.

What it is

The Arm Mali GPU kernel driver mishandles GPU memory operations, allowing a use-after-free (CWE-416) in which freed memory can be accessed again. A local non-privileged user can trigger it, and the flaw affects the Midgard, Bifrost, Valhall and 5th Gen GPU architecture kernel drivers. It matters because freed kernel memory exposure can leak sensitive data and is a common building block for privilege escalation in GPU drivers.

Impact

An attacker gains read access to already freed memory, which can disclose sensitive kernel or process data (CVSS confidentiality impact is High). The record shows no integrity or availability impact, so code execution or privilege escalation is not established by the supplied facts.

Attack surface

Reached locally: the vector is AV:L with low attack complexity, low privileges required and no user interaction (PR:L/UI:N). Any local unprivileged process able to issue GPU memory operations through the Mali driver can attempt it; no remote or network path is described.

Exploitation

CISA added it to the Known Exploited Vulnerabilities catalog on 2023-10-03 with a remediation due date of 2023-10-24, indicating known exploitation in the wild. EPSS is low (0.011, ~64th percentile) and no ransomware campaign use is documented.

What to do

  • Apply the vendor's Mali GPU driver fix per Arm Security Center guidance as the first action.
  • If no patch can be applied, follow CISA's required action: apply vendor mitigations or discontinue use of the affected product.
  • Restrict local access to systems using affected Mali GPUs so untrusted users cannot run code that issues GPU memory operations.
  • Track the CISA KEV due date (2023-10-24) and confirm remediation status for all affected driver variants (Midgard, Bifrost, Valhall, 5th Gen).

Detection

  • Monitor for crashes or anomalous behavior in the Mali GPU kernel driver (kernel oops, driver fault logs) that could indicate use-after-free triggering.
  • Hunt for local processes making unusual or repeated GPU memory allocation/free sequences, especially from non-privileged users.
  • Correlate local exploitation attempts with subsequent suspicious activity such as kernel memory disclosure or privilege escalation attempts.
  • Verify driver versions against Arm's advisory to identify unpatched hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-4211 to the Known Exploited Vulnerabilities catalog on 3 October 2023 as "Arm Mali GPU Kernel Driver Use-After-Free Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 24 October 2023.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-4211 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2022-38181Arm Mali GPU kernel driver use-after-free via mishandled GPU memory operationsThe Arm Mali GPU kernel driver mishandles GPU memory operations, allowing unprivileged users to access freed memory (CWE-416 use-after-free). It affe…KEVEPSS 14%analysed8.8CVE-2021-29256Arm Mali GPU kernel driver use-after-free allows privilege escalationThe Arm Mali GPU kernel driver contains a use-after-free (CWE-416) that an unprivileged user can trigger to access freed memory. Successful exploitat…KEVEPSS 3.0%analysed8.8CVE-2021-28663Arm Mali GPU kernel driver use-after-free privilege escalationThe Arm Mali GPU kernel driver mishandles GPU memory operations, producing a use-after-free in Bifrost, Valhall and Midgard drivers. A local attacker…KEVEPSS 12%analysed8.8CVE-2021-28664Arm Mali GPU kernel driver out-of-bounds write allows privilege escalationThe Arm Mali GPU kernel driver lets an unprivileged user gain read/write access to read-only pages, causing memory corruption. This can lead to privi…KEVEPSS 5.4%analysed7.8CVE-2024-4610Arm Mali GPU kernel driver use-after-free lets local user access freed memoryThe Arm Bifrost and Valhall GPU kernel drivers contain a use-after-free (CWE-416) reachable by a local non-privileged user performing improper GPU me…KEVEPSS 0.76%analysed7.8CVE-2022-22706Arm Mali GPU Kernel Driver read-only memory write flawThe Arm Mali GPU kernel driver lets a non-privileged user gain write access to read-only memory pages, a memory buffer overflow (CWE-119) affecting M…KEVEPSS 1.1%analysed3.3CVE-2023-26083Arm Mali GPU Kernel Driver memory leak exposes kernel metadataThe Arm Mali GPU kernel driver has a memory leak (CWE-401) across Midgard r6p0-r32p0, Bifrost r0p0-r42p0, Valhall r19p0-r42p0, and Avalon r41p0-r42p0…KEVEPSS 1.2%analysed9.8CVE-2022-28349Arm bifrost gpu kernel driver use after free vulnerabilityArm Mali GPU Kernel Driver has a use-after-free: Midgard r28p0 through r29p0 before r30p0, Bifrost r17p0 through r23p0 before r24p0, and Valhall r19p…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2023-4211), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.