CVE-2023-4969
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/01/2024
Last modified:
20/06/2025
Description
A GPU kernel can read sensitive data from another GPU kernel (even from another user or app) through an optimized GPU memory region called _local memory_ on various architectures.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:khronos:opencl:*:*:*:*:*:*:*:* | 3.0.11 (including) | |
| cpe:2.3:a:khronos:vulkan:*:*:*:*:*:*:*:* | 1.3.224 (including) | |
| cpe:2.3:a:imaginationtech:ddk:*:*:*:*:*:*:*:* | 23.2 (including) | |
| cpe:2.3:o:amd:instinct_mi300x_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:amd:instinct_mi300x:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:amd:instinct_mi300a_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:amd:instinct_mi300a:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:amd:instinct_mi250_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:amd:instinct_mi250:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:amd:instinct_mi210_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:amd:instinct_mi210:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:amd:instinct_mi100_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:amd:instinct_mi100:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:amd:radeon_instinct_mi50_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:amd:radeon_instinct_mi50:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://blog.trailofbits.com
- https://kb.cert.org/vuls/id/446598
- https://registry.khronos.org/OpenCL/specs/3.0-unified/html/OpenCL_API.html#_fundamental_memory_regions
- https://registry.khronos.org/vulkan/specs/1.3-extensions/html/index.html
- https://www.kb.cert.org/vuls/id/446598
- https://blog.trailofbits.com
- https://kb.cert.org/vuls/id/446598
- https://registry.khronos.org/OpenCL/specs/3.0-unified/html/OpenCL_API.html#_fundamental_memory_regions
- https://registry.khronos.org/vulkan/specs/1.3-extensions/html/index.html
- https://www.kb.cert.org/vuls/id/446598



