CVE detail
CVE-2023-4211
A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.0 · diversity 11.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
10 source links · newest first
Arm warns that CVE-2024-4610, a Mali GPU kernel driver vulnerability addressed two years ago, is exploited in attacks.
newswww.securityweek.comJun 11, 2024, 10:02 AMMore than 60 of the Adobe, Google, Android, Microsoft, Mozilla and Apple zero-days that have come to light since 2016 attributed to spyware vendors.
newswww.securityweek.comFeb 6, 2024, 10:49 AM- Week in review: Patch Tuesday forecast, 9 free ransomware guides, Cybertech Europe 2023Help Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Photos: Cybertech Europe 2023 The Cybertech Europe conference and exhibition takes place at La Nuvola Convention Center in Rome, and features the latest innovative solutions from dozens of companies and speakers, including senior government officials, C-level executives, and industry trailblazers from Europe and around the world. Cybertech Europe 2023 video walkthrough In this Help Net Security video, we take you … More →
newswww.helpnetsecurity.comOct 8, 2023, 8:30 AM - CISA adds JetBrains TeamCity and Windows flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs
The U.S. CISA added JetBrains TeamCity and Windows vulnerabilities to its Known Exploited Vulnerabilities Catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the JetBrains TeamCity flaw CVE-2023-42793 (CVSS score: 9.8) and Windows bug CVE-2023-28229 (CVSS score: 7.0) to its Known Exploited Vulnerabilities Catalog. Below are the descriptions of the two vulnerabilities: According to Binding Operational Directive […]
newssecurityaffairs.comOct 5, 2023, 1:03 PM - Update your Android devices now! Google patches two actively exploited vulnerabilitiesMalwarebytes Labs
Google has patched 53 vulnerabilities in its Android October security updates, two of which are known to be actively exploited. Google’s security bulletin notes that…
newswww.malwarebytes.comOct 4, 2023, 2:28 PM - Qualcomm patches 3 actively exploited zero-daysHelp Net Security
Qualcomm has fixed three actively exploited vulnerabilities (CVE-2023-33106, CVE-2023-33107, CVE-2023-33063) in its Adreno GPU and Compute DSP drivers. Vulnerabilities exploited in Qualcomm GPU and DSP drivers The US-based semiconductor company has been notified by Google Threat Analysis Group and Google Project Zero that CVE-2023-33106, CVE-2023-33107, CVE-2023-33063, and CVE-2022-22071 “may be under limited, targeted exploitation”. CVE-2022-22071 is an older use-after-free vulnerability found in Automotive Android OS and patched in May 2022. Additional information about the three … More →
newswww.helpnetsecurity.comOct 4, 2023, 1:43 PM - Qualcomm Patches 3 Zero-Days Reported by GoogleSecurityWeek
Qualcomm has patched more than two dozen vulnerabilities, including three zero-days that may have been exploited by spyware vendors.
newswww.securityweek.comOct 4, 2023, 9:00 AM Arm has patched a new security flaw in its Mali GPU kernel drivers that allowed improper GPU memory processing operations to be carried out by a local non-privileged user. Yet without a CVSS score, the vulnerability, dubbed CVE-2023-4211, was reported to have active exploitations in the wild. “A local non-privileged user can make improper GPU memory […]
newswww.csoonline.comOct 3, 2023, 1:13 PMA vulnerability (CVE-2023-4211) in the kernel drivers for several Mali GPUs “may be under limited, targeted exploitation,” British semiconductor manufacturer Arm has confirmed on Monday, when it released drivers updated with patches. Arm’s Mali GPUs are used on a variety devices, most prominently on Android phones by Google, Samsung, Huawei, Nokia, Xiaomi, Oppo, and other manufacturers. About CVE-2023-4211 CVE-2023-4211 stems from improper GPU memory processing and allows a local non-privileged to gain access to already … More →
newswww.helpnetsecurity.comOct 3, 2023, 11:13 AMThe October 2023 security update for Android patches two vulnerabilities exploited in attacks, both likely linked to spyware vendors.
newswww.securityweek.comOct 3, 2023, 9:30 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2024-0671CVSS 6.8 · Medium
Use After Free vulnerability in Arm Ltd Midgard GPU Kernel Driver, Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kerne…
- CVE-2023-6241CVSS 7.0 · High
Use After Free vulnerability in Arm Ltd Midgard GPU Kernel Driver, Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kerne…
- CVE-2023-6143CVSS 8.4 · High
Use After Free vulnerability in Arm Ltd Midgard GPU Kernel Driver, Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kerne…
- CVE-2025-3212CVSS 5.3 · Medium
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privile…
- CVE-2025-0819CVSS 7.8 · High
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privile…
- CVE-2025-0427CVSS 7.8 · High
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privile…