Vulnerabilities > CVE-2023-4969 - Memory Leak vulnerability in multiple products
Attack vector
LOCAL Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
A GPU kernel can read sensitive data from another GPU kernel (even from another user or app) through an optimized GPU memory region called _local memory_ on various architectures.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
References
- https://blog.trailofbits.com
- https://blog.trailofbits.com
- https://kb.cert.org/vuls/id/446598
- https://kb.cert.org/vuls/id/446598
- https://registry.khronos.org/OpenCL/specs/3.0-unified/html/OpenCL_API.html#_fundamental_memory_regions
- https://registry.khronos.org/OpenCL/specs/3.0-unified/html/OpenCL_API.html#_fundamental_memory_regions
- https://registry.khronos.org/vulkan/specs/1.3-extensions/html/index.html
- https://registry.khronos.org/vulkan/specs/1.3-extensions/html/index.html
- https://www.kb.cert.org/vuls/id/446598
- https://www.kb.cert.org/vuls/id/446598