ARM has disclosed information about three vulnerabilities in the drivers for its GPUs used in Android, ChromeOS, and Linux distributions. These vulnerabilities allow an unprivileged local user to execute their code with kernel privileges. The October security report on the Android platform notes that prior to the release of a fix, one of the vulnerabilities (CVE-2023-4211) was already exploited by malicious actors in active exploits for targeted attacks (0-day). For example, the vulnerability can be used in malware distributed through dubious sources to gain full access to the system and install components that spy on the user.
Vulnerabilities found:
- CVE-2023-4211 — improper memory operation with the GPU can lead to access to already freed system memory, which may be utilized during the execution of other tasks in the kernel. The vulnerability is fixed in driver update r43p0 for Mali GPUs based on Bifrost and Valhall microarchitectures, as well as 5th generation ARM GPUs. No driver update has been issued for Midgard series GPUs.
A fix is also offered as part of the September updates for Chrome OS branches 114/115/116 and the October Android update. The vulnerable GPU models are used in smartphones such as Google Pixel 7, Samsung S20 and S21, Motorola Edge 40, OnePlus Nord 2, Asus ROG Phone 6, Redmi Note 11, 12, Honor 70 Pro, RealMe GT, Xiaomi 12 Pro, Oppo Find X5 Pro, Reno 8 Pro, and some devices with Mediatek chips.
- CVE-2023-33200 — improper operations with the GPU can lead to a race condition and access to memory already freed by the driver. The vulnerability is fixed in driver updates r44p1 and r45p0 for Mali GPUs based on Bifrost and Valhall microarchitectures, as well as 5th generation ARM GPUs.
- CVE-2023-34970 — improper operations with the GPU can lead to a buffer overflow and access to memory beyond the allocated buffer. The vulnerability is fixed in driver updates r44p1 and r45p0 for Mali GPUs based on the Valhall microarchitecture and 5th generation ARM GPUs.
The October report on vulnerabilities in Android mentions a total of 53 vulnerabilities, of which 5 have been assigned a critical severity level and the others a high severity level. Critical issues allow for remote attacks that execute code on the system. Issues marked as dangerous allow code execution via manipulation of local applications in the context of a privileged process. Three critical issues (CVE-2023-24855, CVE-2023-28540, and CVE-2023-33028) have been identified in proprietary Qualcomm components, and two (CVE-2023-40129, CVE-2023-4863) in the system (in libwebp and the Bluetooth stack). In total, 5 vulnerabilities were identified in ARM components, 3 in MediaTek, 1 in Unisoc, and 17 in Qualcomm (report from Qualcomm). Two vulnerabilities (one in the ARM GPU and one in libwebp) are noted as already being exploited by attackers (0-day).
Source: opennet.ru
