CVE-2023-26083General(arm / 5th_gen_gpu_architecture_kernel_driver)

MEDIUMCVSS 3.3 · LOWCISA KEV

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch arm 5th_gen_gpu_architecture_kernel_driver systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Memory leak vulnerability in Mali GPU Kernel Driver in Midgard GPU Kernel Driver all versions from r6p0 - r32p0, Bifrost GPU Kernel Driver all versions from r0p0 - r42p0, Valhall GPU Kernel Driver all versions from r19p0 - r42p0, and Avalon GPU Kernel Driver all versions from r41p0 - r42p0 allows a non-privileged user to make valid GPU processing operations that expose sensitive kernel metadata.

4.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-04-28. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-401

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 5th_gen_gpu_architecture_kernel_driver
  • bifrost_gpu_kernel_driver
  • midgard_gpu_kernel_driver
  • valhall_gpu_kernel_driver

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-01-29); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
5th_gen_gpu_architecture_kernel_driverbifrost_gpu_kernel_drivermidgard_gpu_kernel_drivervalhall_gpu_kernel_driver

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-01-29: 1Mentions · 2026-07-13: 1PoC Mentioned / Linked · 2026-07-13: 1Exploit Tool / Code · 2026-07-13: 1Patch / Workaround · 2026-07-13: 1Technical Details · 2026-01-29: 1Technical Details · 2026-07-13: 101-2907-13
Signal classification2 categories
General
150.0%
PoC
150.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-01-291
General1
2026-07-131
PoC1
Full discourse2 posts
  • 8kSec@8kSec
    PoC

    This deep dive breaks down CVE-2023-26083, where the Mali GPU driver serialized raw kernel pointers into a timeline stream ring buffer that unprivileged apps could acquire via ioctl and read using normal read operations. KASLR bypass primitive with user-space code: https://8ksec.io/cve-2023-26083-kernel-pointer-leakage-in-mali-gpus-timeline-stream-message-buffers Remained exploitable on Pixel 8 months after the announced patch. For researchers interested in topics like this, and our Offensive Android Internals course goes deeper into Android kernel internals, Mali GPU research, DAC/CAP/RKP/MTE, native fuzzing with Frida and AFL++, leads to the CASR certification. https://academy.8ksec.io/course/offensive-android-internals Follow @8kSec for more Android kernel research

    Post summary

    The post dissects CVE‑2023‑26083, detailing a kernel pointer leakage that enables a KASLR bypass via user‑space code, cites a PoC link, notes the bug was still exploitable after the patch, and invites researchers to study it further through their Android internals course.

    06047284.0K
    3.6K followersView on X
  • 8kSec@8kSec
    General

    What’s interesting about CVE-2023-26083 isn’t the existence of a pointer leak, but the path it takes: a user-readable timeline stream ring buffer carrying raw kernel pointers. 🧵That detail changes how you reason about the attack surface and where to look for similar issues. Read the full analysis here: https://8ksec.io/cve-2023-26083-kernel-pointer-leakage-in-mali-gpus-timeline-stream-message-buffers/

    Post summary

    The post highlights CVE‑2023‑26083’s pointer leak via a timeline stream buffer and points readers to a detailed analysis article.

    08048193.2K
    3.1K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Apparm5th_gen_gpu_architecture_kernel_driver---
Apparmbifrost_gpu_kernel_driver---
Apparmmidgard_gpu_kernel_driver---
Apparmvalhall_gpu_kernel_driver---

Explore more