LOW CISA KEV

CVE-2023-26083

CVSS v3

3.3

LOW

EPSS Score

7.1%

exploit probability

CISA KEV

Yes

known exploited

Exploitation

SSVC status

Description

Memory leak vulnerability in Mali GPU Kernel Driver in Midgard GPU Kernel Driver all versions from r6p0 - r32p0, Bifrost GPU Kernel Driver all versions from r0p0 - r42p0, Valhall GPU Kernel Driver all versions from r19p0 - r42p0, and Avalon GPU Kernel Driver all versions from r41p0 - r42p0 allows a non-privileged user to make valid GPU processing operations that expose sensitive kernel metadata.

CISA Known Exploited Vulnerability

Date Added
4/7/2023
Patch Due Date
4/28/2023
Ransomware Use
Unknown

Technical details

Published
4/6/2023

Frequently asked questions

What is CVE-2023-26083?

Memory leak vulnerability in Mali GPU Kernel Driver in Midgard GPU Kernel Driver all versions from r6p0 - r32p0, Bifrost GPU Kernel Driver all versions from r0p0 - r42p0, Valhall GPU Kernel Driver all versions from r19p0 - r42p0, and Avalon GPU Kernel Driver all versions from r41p0 - r42p0 allows a non-privileged user to make valid GPU processing operations that expose sensitive kernel metadata.

Is CVE-2023-26083 actively exploited?

Yes. CVE-2023-26083 is on the CISA Known Exploited Vulnerabilities (KEV) catalog, meaning it has been confirmed as actively exploited in the wild. CISA requires federal agencies to patch by 4/28/2023.

What is the CVSS score for CVE-2023-26083?

CVE-2023-26083 has a CVSS v3 base score of 3.3 (LOW severity).

Is CVE-2023-26083 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.