CVE-2023-4969

amd athlon_3000g_firmware: Sicherheitsluecke

mediumEPSS 1.2%

Affected

  • khronos/opencl between *..3.0.11
  • khronos/vulkan between *..1.3.224
  • imaginationtech/ddk between *..23.2

Description

A GPU kernel can read sensitive data from another GPU kernel (even from another user or app) through an optimized GPU memory region called _local memory_ on various architectures.

Affected operating systems

  • other

    amd / athlon_3000g_firmware

  • other

    amd / instinct_mi100_firmware

  • other

    amd / instinct_mi210_firmware

  • other

    amd / instinct_mi250_firmware

  • other

    amd / instinct_mi300a_firmware

  • other

    amd / instinct_mi300x_firmware

  • other

    amd / radeon_instinct_mi25_firmware

  • other

    amd / radeon_instinct_mi50_firmware

  • other

    amd / radeon_pro_v520_firmware

  • other

    amd / radeon_pro_v620_firmware

  • other

    amd / radeon_pro_w5500x_firmware

  • other

    amd / radeon_pro_w5700x_firmware

  • other

    amd / radeon_pro_w6300m_firmware

  • other

    amd / radeon_pro_w6400_firmware

  • other

    amd / radeon_pro_w6500m_firmware

  • other

    amd / radeon_pro_w7500_firmware

  • other

    amd / radeon_pro_w7600_firmware

  • other

    amd / radeon_rx_5300_firmware

  • other

    amd / radeon_rx_5300m_firmware

  • other

    amd / radeon_rx_5300xt_firmware

  • other

    amd / radeon_rx_5500_firmware

  • other

    amd / radeon_rx_5500m_firmware

  • other

    amd / radeon_rx_5500xt_firmware

  • other

    amd / radeon_rx_5600_firmware

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

imaginationtechddk
23.2
khronosopencl
3.0.11
khronosvulkan
1.3.224

Metrics

6.5
Source: nvd-v3
66.9 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
medium
no public PoC known
1.2 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2024-01-16 17:01 UTC

References & sources

Linked advisories